<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Provide VLAN and ISID without policy in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/65419#M72</link>
    <description>I have EXOS and Fabric with Fabric Attach.&lt;BR /&gt;I want dynamic VLAN and ISID assignment without using a policy.&lt;BR /&gt;So the switch gets the VLAN AND the ISID dynamically. &lt;BR /&gt;&lt;BR /&gt;At which point I have to configure the ISID?</description>
    <pubDate>Fri, 26 Aug 2022 12:41:46 GMT</pubDate>
    <dc:creator>ChristianK</dc:creator>
    <dc:date>2022-08-26T12:41:46Z</dc:date>
    <item>
      <title>Provide VLAN and ISID without policy</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/65419#M72</link>
      <description>I have EXOS and Fabric with Fabric Attach.&lt;BR /&gt;I want dynamic VLAN and ISID assignment without using a policy.&lt;BR /&gt;So the switch gets the VLAN AND the ISID dynamically. &lt;BR /&gt;&lt;BR /&gt;At which point I have to configure the ISID?</description>
      <pubDate>Fri, 26 Aug 2022 12:41:46 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/65419#M72</guid>
      <dc:creator>ChristianK</dc:creator>
      <dc:date>2022-08-26T12:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Provide VLAN and ISID without policy</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/92813#M306</link>
      <description>&lt;P&gt;Just use proper radius attribute&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Adam_Minowski_0-1661990857143.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6106i098450CA4AD25BFA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Adam_Minowski_0-1661990857143.png" alt="Adam_Minowski_0-1661990857143.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Attach new "Radius attributes to send" config to EXOS switch.&lt;/P&gt;&lt;P&gt;Then in NAC Profile add ISID number to Custom1 field:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Adam_Minowski_1-1661990979918.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6107i4263C765F78597F9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Adam_Minowski_1-1661990979918.png" alt="Adam_Minowski_1-1661990979918.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Of course you can remove ISID from Policy config and still use Policy with conjunction to FA (eg. for traffic filtering)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Adam_Minowski_4-1661991248324.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6110iDAE518B904DE5C14/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Adam_Minowski_4-1661991248324.png" alt="Adam_Minowski_4-1661991248324.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 00:14:15 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/92813#M306</guid>
      <dc:creator>Adam_Minowski</dc:creator>
      <dc:date>2022-09-01T00:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: Provide VLAN and ISID without policy</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/119394#M2099</link>
      <description>&lt;P&gt;Hi Apologies for bringing up old post but this is sort of what i'm looking for to answer something in 2025 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; but if i was mapping untagged and tagged vlans to a port (such as 3rd party access point with multiple SSID's) how do you achieve multiple dynamic VLAN and I-SID mappings with exos and FA? do you have an example? thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 11:41:16 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/119394#M2099</guid>
      <dc:creator>gtkins121</dc:creator>
      <dc:date>2025-07-28T11:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Provide VLAN and ISID without policy</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/119396#M2101</link>
      <description>&lt;P&gt;Best option is to use multiple FA-VLAN-ISIDs but you need EXOS 33.2. With that version you can use multiple VLAN:ISID mappings:&lt;BR /&gt;&lt;STRONG&gt;FA-VLAN-ISID="10:120010,11:120011,123:120123"&lt;BR /&gt;&lt;/STRONG&gt;The first VLAN:NSI entry specified is the PVID vlan and the other vlans as egress VLANs&lt;/P&gt;&lt;P&gt;If you don't have EXOS 33.2 then Policy is the only sensible way.&lt;/P&gt;&lt;P&gt;Policy with control "Permit" and VLAN Egress definitions for tagged vlans only.&lt;BR /&gt;NAC would respond with Policy name with Filter-ID and FA-VLAN-ISID for untagged traffic.&lt;BR /&gt;Example:&lt;BR /&gt;Filter-Id=Enterasys:version=1:policy=ACCESS-POINT&lt;BR /&gt;FA-VLAN-ISID=11:120011&lt;/P&gt;&lt;P&gt;ACCESS-POINT Policy profile includes "Permit" permission and only "tagged" VLANs (in VLAN Egress tab in Policy Manager)&lt;BR /&gt;FA-VLAN-ISID would set up untagged vlan 11 and i-sid 120011&lt;/P&gt;&lt;P&gt;There is a drawback - tagged vlans will not be FA-signalled on uplink port. If you want such behavior and you want to have it automated, then you can use i-sid offset option&lt;/P&gt;&lt;P&gt;# configure fabric attach isid-nsi-offset &amp;lt;number&amp;gt;&lt;BR /&gt;In such case dynamic VLANs can have i-sid auto assigned by switch itself. Eg when you would configure:&lt;BR /&gt;#&amp;nbsp;configure fabric attach isid-nsi-offset 120000&lt;BR /&gt;When dynamic VLAN is created based on Radius response then switch would map it to i-sid adding vlan to offset. For example if vlan would be 100 then i-sid would be 120100 (as per example)&lt;/P&gt;&lt;P&gt;You can also&amp;nbsp;create a python script which will be triggered by UPM and would install all needed fa mappings. Unfortunately distribution of the script to all switches could be the different issue. In one word it is complicated so I don't recommend go that way.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;One very important thing.&lt;/STRONG&gt; When you would use Policy, there is an option to enable &lt;STRONG&gt;"AP Aware"&lt;/STRONG&gt; feature on Policy profile. This feature would disable consecutive auth requests on the port when AP Aware Policy is applied. It is hugely important to avoid double auth requests&amp;nbsp; for same user/endpoint. Why double? First one would come from WiFi and then, once the endpoint is permitted by WIFi, second session would come from a switch port. It's because port itself is netlogin-enabled to authenticate access point.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 13:20:22 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/119396#M2101</guid>
      <dc:creator>Adam_Minowski</dc:creator>
      <dc:date>2025-07-28T13:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Provide VLAN and ISID without policy</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/119408#M2102</link>
      <description>&lt;P&gt;Thanks! got to 33.4.1 today and the multiple vlan on port works yes. only issue im trying to work through now is the NSI mapping is not working. the vlans dynamically create with fabric attach just missing the relevant ISID/NSI mapping.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 12:24:17 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/119408#M2102</guid>
      <dc:creator>gtkins121</dc:creator>
      <dc:date>2025-07-29T12:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: Provide VLAN and ISID without policy</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/120464#M2132</link>
      <description>&lt;P&gt;To provide a VLAN and ISID (Instance ID) without a policy, you can use a command-line interface (CLI) to manually configure the fabric attach (FA) attributes, which maps the VLAN to the ISID. Alternatively, you can write a custom UPM profile with a script to trigger the mapping, though this is a more complex workaround for platforms like Extreme Networks.&amp;nbsp;&lt;A href="https://seminolecountyclerkofcourt.click/" target="_self"&gt;Seminole County Clerk of Court&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 08:54:09 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/provide-vlan-and-isid-without-policy/m-p/120464#M2132</guid>
      <dc:creator>Wough1948</dc:creator>
      <dc:date>2025-10-09T08:54:09Z</dc:date>
    </item>
  </channel>
</rss>

