I am in the middle of an ISE proof of concept and have been running the product through its paces. Since nearly all of my access points are in FlexConnect mode (formerly known as H-REAP), they require additional configuration to allow dynamic VLAN assignment with ISE. FlexConnect supports local switching which allows you to map a local VLAN ID from the AP’s switch to an SSID instead of tunneling all traffic back to the Wireless LAN Controller to be switched centrally.
In order to dynamically assign a VLAN ID with an ISE authorization profile, the VLAN must exist on the access point. FlexConnect Groups accomplish this task.
From the Wireless menu, select FlexConnect Groups and click the New button. Once you create the group, click the group name to open the edit menu (seen below). On the General tab, add the access points to the FlexConnect group. To add the VLAN ID, select the ACL Mapping tab and then the “AAA VLAN-ACL mapping” tab. Enter the VLAN ID and select the ingress and egress ACLs. In my case, I selected “none”. Click Add and then Apply.
Your VLAN ID’s have been added to your access point and can be assigned with an ISE authorization policy.
For more information see Cisco documentation
Screen shot from Cisco 5508 Wireless Lan Controller version 7.4.100.0
Alan Cowan says
Just what I was looking for! Thanks!
t2ok says
Man, I was looking for this and had problems achieving it, thank you so much. Now I have clients in the correct Vlans
Aldrin Luigi says
Thanks a lot for sharing this information.
alex bertran says
It works for me for WLC 5520 v8.5.135.0 but it is not working on 8.10.130.0