DHCP Vendor Class of Server2003

Hi all,
1. There are two clients with different Vendor ID (send via DHCP DISCOVER option 60), for example, client A's option 60 is AAA, B's is BBB.
2. I had created two Vendor Classes on a Windows Server2003. They match the Vendor ID of client A and B.
3. I had created two options (for example, option 150) under the tow Vendor Classes, and added them in a same DHCP scope. I wanna client A and B can get different option 150 message from DHCP server.
4. After my settings, DHCP server would send different respondence to identifying clients. However, it responds via option 43, not option 150 (which is I set) .
What can I do if I want DHCP server to respond via option 150 that I set?
Thanks for your reply.

Hi,
Sorry for my late reply.
Does the problem persist?
PLease refer to the link below to know how to configure vendor class
http://support.microsoft.com/kb/240247
Best Regards
Quan Gu

Similar Messages

  • Dhcp client option 60 vendor class windows 7 - HOW TO CHANGE?

    Hi,
    I would like to change the vendor class (dhcp option 60) on my Windows 7 box (not server).
    I have a requirement to connect to a dhcp server that requires a unique vendor class that happens to not be "MSFT 5.0".
    Eventually we are going to be running Windows 7 embedded. A solution specific to that platform would also be acceptable.
    How does one change that vendor class without editing hacking a dll in windows?
    Again, this is Windows 7, NOT Windows 7 server.
    And again, this is the VENDOR CLASS, not the class id.
    Please help.
    Thanks

    Hi,
    Use this following command:
    ipconfig /setclassid
    To set DHCP class ID information at a client computer
    http://technet.microsoft.com/en-us/library/cc783756(v=ws.10).aspx
    Alex Zhao
    TechNet Community Support

  • What are the following:1)Cisco 1600 Series IOS WIRELESS LAN RECOVERY. 2)Service Provider Option 60 for Vendor Class Idenfier

    What are the following:1)Cisco 1600 Series IOS WIRELESS LAN RECOVERY. 2)Service Provider Option 60 for Vendor Class Idenfier
    These items are listed with 1600 series AP but I'm unable to understand what are these things & the use of them

    DHCP Option 60:  Go HERE.

  • Vendor Evalution - Vendor Class

    Hi
    1. What is the exact purpose of Vendor class ? How it can be used in Vendor Evaluation and other areas ?
    2. Can we group some Vendors in to a Vendor class so that we can assign the Weighting key to the Vendor Class instead of Vendor by Vendor in Vendor Evalution.
    Thanks
    Maruthi

    Hi Experts
    Any related answers or related research.??
    Any documentation or related links in SAP Help ?
    Regards
    Maruthi Ram

  • CNR DHCP Client-class

    We are using CNR with multiple scopes to provide ip addressing for both computers and IPTV set top boxes. The STB's require boot params in dhcp option-131 and option-240. I have set up a client-class-policy that contains the two options and when I set up a client with an exact mac address, then the information is provided correctly.
    The problem is we have hundreds of STB's. How do I get CNR to generalize the client mac address to just the first 3 bytes?
    I have tried creating a client with 00:00:00 for the last three bytes and then altering the dhcp-client-identifier to match, but it doesn't work.
    The docs state that you can create a client-lookup-id expression but shows no examples.
    Thanks.

    Reread the docs closer and found that the environment parameter 'default-client-class-name' is only visible in the pre-client-lookup extension. So in the post-packet-decode extension I check the request parameter 'dhcp-class-identifier' and then set a environment parameter stb-type to a class name.
    In the pre-client-lookup I check to see if the stb-type is in the environment dictionary. If it is then I set 'default-client-class-name' to that value. This forces the DHCP to use the client-class of the same name as the default for this DHCP request. Since I set the option 131 in the appropriate client-class-policy then it all works. Don't even need a client set up at all.
    Thanks for the response on expressions. Looks like I may have been able to do it that way too.

  • DHCP - Two Class C Subnets

    Our OS X (10.4.11) server is not handing out ip addresses via DHCP. The server is set to hand out ip addresses from a second Class C subnet that has been added to the router. No clients are ever listed and remains at 0.
    Perhaps it has something to do with the new AirPort Extreme base stations. How do you turn off "distribute IP addresses"?
    Could something be set wrong in the DNS service that is causing this?
    Does something else need to be done in the router so that both subnets are recognized?
    I would appreciate it if someone could steer me to a helpful site.
    This has successfully been done at two different locations here with older base stations and on networks that have only the main Class C network.
    Thanks for any help.

    IIRC, the server will start handing out IP addresses from the lowest number and work up.
    Therefore I wouldn't expect the second /24 network to be used until 254 IP addresses have already been used in the first /24.
    In other words, the second /24 network is used as an overflow.
    The server does have its own IP address in the second /24 network, right? I haven't ever tried handing out DHCP addresses for a subnet that the server doesn't have a leg in.

  • DHCP Vendor ID

    Hi,
    How I can changed the DHCP option Vendor ID?
    With Linux I should changed it with /etc/dhcp3/dhclient.conf file.
    What about Darwin ?
    Thx
    Message was edited by: ancrou
    Message was edited by: ancrou

    I don't know the specific tag you need, but the DHCP server is managed within bootpd and /etc/bootpd.plist - an XML file containing all the BOOTP/DHCP/NetBoot configuration data.

  • Text Characteristic from Vendor Class. System

    HI Gurus!
    I needed in a report a characteristic that came from Vendor Classification System in R/3. To get it, i enhanced the Datasource 0VENDOR_ATTR with the new characteristic attribute and used the function module 'BAPI_CLASS_GET_CLASSIFICATIONS' to get the characteristic value.
    My problem now is that i need also to get the texts from this characteristic. How can i extract this texts to my custom infoobject. I was wondering that the only eay was to built a generic texts datasource with a function module... Does anybody know any alternative?
    Thanks in advance.
    Nuno

    Hi
    If Text keeps on change then you have to create a datasource which is normal.
    If text doesn't change then do textfile upload.
    To get the text , goto domain of the that field in R/3 and select value range .Save the values in  CSV format and text file upload.
    Hope ti helps.
    Regards,
    Chama.

  • Setting up Oracle JVM and vendor Classes

    Hello All,
    I am trying to setup a Java Stored Procedure that
    writes messages to IBM MQSeries Queue. MQSeries has
    three client jar files (these jar files use CORBA
    classes which are part of the JDK installation).
    This Java client works well outside Oracle but
    we are getting exceptions such ClassNotFoundException.
    Does has experience on setting up such classes
    within Oracle JVM? Are there extra documenations
    we can use to guide us in setting up?
    Many thanks in advance.

    What version of the Oracle database are you using? What version of the JDK do IBM's classes require? My hunch is that IBM's classes may require a more recent version of the JDK than is currently installed in your database.
    Justin
    Distributed Database Consulting, Inc.
    www.ddbcinc.com/askDDBC

  • What are the endpoints attributes collected by NAC Profiler through SNMP and DHCP?

    Hi Everyone,
    Please help on this.
    I want to know what are the endpoints attributes collected by NAC Profiler to discover and profile the endpoints.through SNMP protocol and DHCP protocol.
    Also if anybody can explain a simple used case on this.
    Please guide me on this.
    Thanks in advance.
    Thanks,
    Abuzar.

    Hi,
    SNMP
    =====
    NetMap queries network devices via SNMP for:
    System information
    Interface information
    Bridge information
    802.1X information (PAE MIB)
    Routing/IP information
    CDP MIB Information
    This information is used to Build and maintain a model of the network topology and endpoint discovery.
    NetMap uses SNMP Get, GetNext and GetBulk (when available) requests to  query the SNMP agents running on the network infrastructure devices to  gather specific Management Information Base (MIB) objects about their  status based on device type (Layer 2 or Layer 3).
    In addition to polling each network device for all MIB data at a regular  interval, NetMap may also be commanded to poll port-specific  information when the NAC Profiler system is notified that an endpoint  has joined or left the network via SNMP traps sent by devices at the  network edge, switches typically.
    Upon receipt and verification of a link state (link up, link down) or  MAC notification trap, NetTrap will notify the NAC Profiler Server that a  change has occurred on the network edge (endpoint joined or left a  network port). If the trapping device is in the NAC Profiler  configuration, the NetMap component module assigned to poll the device  that sent the trap will be commanded by the Server module to initiate a  poll of the device's port information to determine the change to the  endpoint topology that resulted in the trap being sent by the network  device.
    The information gathered by NetMap is processed by the Server  accordingly to update the network topology, noting the endpoint joining  or leaving a port. Note that NetMap SNMP polling of network devices  resulting from a trap is localized to the port specified in the trap.  This is unlike the regular polling that occurs at the frequency  specified for each device type (L2 and L3) which gathers all SNMP  information from the device used by the NAC Profiler system.
    DHCP:
    =====
    The NetWatch module listens for traffic including DHCP traffic.
    The module will collect all the DHCP information on the traffic collected, like mac address, ip address,  DHCP Vendor Class Identifier in DHCP request, host name in DHCP request, requested specified options in DHCP request (option 55) and full list of DHCP options supported by the DHCP client as specified in the DHCP request.
    All the endpointe data can then be used to map endpoints with profiles.
    HTH,
    Tiago
    If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

  • How to configure netboot across vlans/DHCP when already a windows bootp server in the mix?

    Hi All,
    We just moved to multiple VLAN's for our Mac's in a mostly WIndows environment. DHCP option 66 points to a Windows Deployment Server & option 67 to the WDS file.
    I've tried  "sudo bless –netboot –server bsdp://10.2.0.1" on a client but get "Netboot scheme bspd not supported on EFI systems".
    I can get changes to the DHCP scopes if needed  -except for the boot server, so I was thinking using something like using DHCP Vendor Class Identifier to specify a different bootp server but have no clues how...
    Any ideas?
    Cheers
    Steve

    You might check out the "How to boot across subnets" page at <http://afp548.com/mactips/>. It has a bunch of info.

  • Clients not able to join more 256 nos

    Hi
    We have using wireless controller CISCO 2125 with 8 nos LWAP 1252, including AP's getting the IP from windows DHCPserver (172.29.70.0/23), when clients reaches 256 nos in controller , then further not able to join in wireless network.
    DHCP vendor class or user class will solve this issue. pl guide me .
    thanks
    Karthik

    Well, it's totally expected then as it's the maximum amount of clients supported by the 2125.
    If you have that amount of client you should look into having more APs and a more powerful WLC. That limit is not just there for marketing purpose. It looks like your network is under-powered compared to its real usage.
    Regards,
    Nicolas
    ===
    Don't forget to rate answers that you find useful

  • ASR 9001 BNG IPoE problems

    Hi,
    I have read and try these guides
    https://supportforums.cisco.com/docs/DOC-23170
    https://supportforums.cisco.com/docs/DOC-19702
    https://supportforums.cisco.com/docs/DOC-19726
    But have some problems , here is my config ( almost same like the guides )
    radius-server host xxx.xxx.xxx.46 auth-port 1812 acct-port 1813!aaa server radius dynamic-author port 3799 client yyy.yyy.yyy.102 vrf default ! client xxx.xxx.xxx.46 vrf default !aaa attribute format MY_AUTH mac-address! aaa attribute format NAS_PORT_FORMAT circuit-id plus remote-id separator .!!aaa radius attribute nas-port format e SSAAPPPPQQQQQQQQQQVVVVVVVVVVUUUU type 32aaa radius attribute nas-port format e SSAAPPPPQQQQQQQQQQVVVVVVVVVVUUUUaaa radius attribute nas-port-id format NAS_PORT_FORMATaaa group server radius RADIUS_GR server xxx.xxx.xxx.46 auth-port 1812 acct-port 1813 source-interface Loopback0!aaa authorization network default group RADIUS_GRaaa accounting subscriber default group RADIUS_GRaaa authorization subscriber AUTH_GR group RADIUS_GRaaa authorization subscriber default group RADIUS_GRaaa authorization subscriber RADIUS_GR group RADIUS_GRaaa authentication subscriber default group RADIUS_GRaaa accounting update periodic 10dhcp ipv4 profile IP_DEFAULT proxy  class IP_DEFAULT   helper-address vrf default yyy.yyy.yyy.102 giaddr zzz.zzz.zzz.1  !  helper-address vrf default yyy.yyy.yyy.102 giaddr zzz.zzz.zzz.1  relay information option  relay information policy keep  relay information option allow-untrusted !   interface Bundle-Ether100.361 proxy profile IP_DEFAULT!ipv4 access-list PERM_ALL 10 permit ipv4 any any 20 permit icmp any any 30 permit ipv4 any any!interface Bundle-Ether100 bundle load-balancing hash dst-ip!!interface Bundle-Ether100.361 ipv4 point-to-point ipv4 unnumbered Loopback100 service-policy type control subscriber IP_PM encapsulation dot1q 361 ipsubscriber ipv4 l2-connected  initiator dhcp !!interface Loopback0 ipv4 address ccc.ccc.ccc.174 255.255.255.255!interface Loopback100 description 4dhcp ipv4 address zzz.zzz.zzz.1 255.255.255.0!interface TenGigE0/0/2/0 bundle id 100 mode on!interface TenGigE0/0/2/1!dynamic-template type ipsubscriber IPSUB_TPL  ipv4 unnumbered Loopback100  ipv4 access-group PERM_ALL ingress  ipv4 access-group PERM_ALL egress !class-map type control subscriber match-any DHCP match protocol dhcpv4 end-class-map!policy-map type control subscriber IP_PM event session-start match-first  class type control subscriber DHCP do-until-failure   5 activate dynamic-template IPSUB_TPL   10 authorize aaa list AUTH_GR format MY_AUTH password cisco  ! ! end-policy-map!
    Without  service-policy type control subscriber IP_PM on the interface , CPE gets ip address and all works.
    The radius server is configured always to autothenticate with access-accept but there are errors
      Total Deadtime: 0s Last Deadtime: 0s
      Timeout: 5 sec, Retransmit limit: 3
      Quarantined: No
      Authentication:
        468 requests, 1 pending, 154 retransmits
        0 accepts, 0 rejects, 0 challenges
        204 timeouts, 417 bad responses, 417 bad authenticators
        0 unknown types, 417 dropped, 0 ms latest rtt
        Throttled: 0 transactions, 0 timeout, 0 failures
        Estimated Throttled Access Transactions: 0
        Maximum Throttled Access Transactions: 0
      The most strange issue is this
    000c.42a8.71e2  0.0.0.0         INIT       57         BE100.361            default    0x0      
    and
    RP/0/RSP0/CPU0:Sep 23 17:08:03.507 : dhcpd[1077]: DHCPD ERROR: TP2468: rib route delete failed, null ifhandle or IPv4 address
    Here is the subscriber session info
    RP/0/RSP0/CPU0:ASR9001#show subscriber session all
    Mon Sep 23 17:08:46.995 EET
    Codes: IN - Initialize, CN - Connecting, CD - Connected, AC - Activated,
           ID - Idle, DN - Disconnecting, ED - End
    Type         Interface                State     Subscriber IP Addr / Prefix                             
                                                    LNS Address (Vrf)                             
    IP:DHCP      No                       CN        -                                   
    RP/0/RSP0/CPU0:ASR9001#show subscriber session all detail
    Mon Sep 23 17:08:48.394 EET
    Interface:                None
    Circuit ID:               000401690107
    Remote ID:                0006001ebd7b2f00
    Type:                     IP: DHCP-trigger
    IPv4 State:               Up Pending, Mon Sep 23 17:08:32 2013
    Mac Address:              000c.42a8.71e2
    Account-Session Id:       000001e0
    Nas-Port:                 67114640
    User name:                unknown
    Outer VLAN ID:            361
    Subscriber Label:         0x0000005f
    Created:                  Mon Sep 23 17:08:32 2013
    State:                    Connecting
    Authentication:           unauthenticated
    Access-interface:         Bundle-Ether100.361
    Policy Executed:
    policy-map type control subscriber IP_PM
      event Session-Start match-first [at Mon Sep 23 17:08:32 2013]
        class type control subscriber DHCP do-until-failure [Succeeded]
          5 activate dynamic-template IPSUB_TPL [Succeeded]
    Session Accounting: disabled
    Last COA request received: unavailable
    Pending Callbacks:
      Waiting for Authorization to complete
      Waiting for Authentication response from AAA

    Hi Alex, i have downgrade my router to 4.3.4, in this version there are no DHCPv4 Server option. how do i get the dhcp server in my router ?
    I have try to connect my demo client, the result is my router doesn't recieved Accept-Access from my Radius and also the routing system still send radius packet from interface physical instead loopback0.
    Access-Request from Router to Radius #  7 09:45:02.753 : radiusd[315]:  RADIUS: Send Access-Request to 202.xxx.xxx.60:1645 id 24, len 254  7 09:45:02.754 : radiusd[315]:  RADIUS:  authenticator FC 30 00 B2 EB 76 ED 27 - 82 51 DF 8C F2 45 AA 6F  7 09:45:02.754 : radiusd[315]:  RADIUS:  Vendor,Cisco        [26]    41        7 09:45:02.754 : radiusd[315]:  RADIUS:   Cisco AVpair        [1]    35      client-mac-address=000f.b0d1.a219  7 09:45:02.754 : radiusd[315]:  RADIUS:  Vendor,Cisco        [26]    34        7 09:45:02.754 : radiusd[315]:  RADIUS:   Cisco AVpair        [1]    28      dhcp-vendor-class=MSFT 5.0  7 09:45:02.754 : radiusd[315]:  RADIUS:  Acct-Session-Id     [44]    10      0400000a  7 09:45:02.754 : radiusd[315]:  RADIUS:  NAS-Port-Id         [87]    13      130/8/0/905  7 09:45:02.754 : radiusd[315]:  RADIUS:  Vendor,Cisco        [26]    19        7 09:45:02.754 : radiusd[315]:  RADIUS:   cisco-nas-port      [2]    13      130/8/0/905  7 09:45:02.754 : radiusd[315]:  RADIUS:  User-Name           [1]     16      000f.b0d1.a219  7 09:45:02.754 : radiusd[315]:  RADIUS:  Service-Type        [6]     6       Outbound[5]   7 09:45:02.754 : radiusd[315]:  RADIUS:  User-Password       [2]     18      *         7 09:45:02.754 : radiusd[315]:  RADIUS:  Vendor,Cisco        [26]    33        7 09:45:02.754 : radiusd[315]:  RADIUS:   Cisco AVpair        [1]    27      parent-if-handle=67111360  7 09:45:02.754 : radiusd[315]:  RADIUS:  NAS-Port-Type       [61]    6       IPOEOVLAN[40]   7 09:45:02.754 : radiusd[315]:  RADIUS:  Event-Timestamp     [55]    6       1389062702  7 09:45:02.754 : radiusd[315]:  RADIUS:  Nas-Identifier      [32]    26      HOSTNAME-BNG  7 09:45:02.754 : radiusd[315]:  RADIUS:  NAS-IP-Address      [4]     6      210.xxx.yyy.2Access-Request from Radius which got from Router #*** Received from 210.xxx.yyy.2 port 51185 ....Code:       Access-RequestIdentifier: 31Authentic:  *<134><174><25><251>a<140><17><170><255>S<191><205>;T<153>Attributes: cisco-avpair = "client-mac-address=000f.b0d1.a219" cisco-avpair = "dhcp-vendor-class=MSFT 5.0" Acct-Session-Id = "0400000b" NAS-Port-Id = "130/8/0/905" Cisco-NAS-Port = "130/8/0/905" User-Name = "000f.b0d1.a219" Service-Type = 5 User-Password = <251><10>h<203><11><203><151><132>i<29><222>@<251>t7<166> cisco-avpair = "parent-if-handle=67111360" NAS-Port-Type = 40 Event-Timestamp = 1389062760 NAS-Identifier = "HOSTNAME-BNG" NAS-IP-Address = 210.xxx.yyy.2##Accept-Access from Radius to Router ##Tue Jan  7 09:42:53 2014: DEBUG: Handling with Radius::AuthFILE: Tue Jan  7 09:42:53 2014: DEBUG: Radius::AuthFILE looks for match with 000f.b0d1.a219 [000f.b0d1.a219]Tue Jan  7 09:42:53 2014: DEBUG: Radius::AuthFILE ACCEPT: : 000f.b0d1.a219 [000f.b0d1.a219]Tue Jan  7 09:42:53 2014: DEBUG: AuthBy FILE result: ACCEPT, Tue Jan  7 09:42:53 2014: DEBUG: Access accepted for 000f.b0d1.a219Tue Jan  7 09:42:53 2014: DEBUG: Packet dump:*** Sending to 210.xxx.yyy.2 port 51185 ....Code:       Access-AcceptIdentifier: 31Authentic:  $U<226><252>4<219><171><228><226>q^<28><135>?<143><175>Attributes:## BUT The Router never recieved Access-Accept Packet from the Radius ##== Current Configuration After Downgrade to 4.3.4 ==radius source-interface Loopback0 vrf defaultradius-server host 202.158.58.60 auth-port 1645 acct-port 1646 key 7 radius-server timeout 10aaa attribute format NAS_PORT_FORMAT circuit-id plus remote-id separator #!aaa attribute format USERNAME_FORMAT mac-addressaaa group server radius radiator server 202.xx.xx.60 auth-port 1645 acct-port 1646 source-interface Loopback0!aaa accounting subscriber default group radiatoraaa authorization subscriber default group radiatoraaa authorization subscriber author_grp group radiatoraaa authentication subscriber default group radiatoraaa accounting update periodic 5dhcp ipv4 profile DHCPv4 proxy  helper-address vrf default 202.xxx.1.34 giaddr 101.aaa.bbb.1  relay information option  relay information policy keep  relay information option allow-untrusted interface GigabitEthernet0/0/0/0.905 proxy profile DHCPv4interface Loopback0 ipv4 address 202.ccc.ddd.233 255.255.255.255interface Loopback2000 ipv4 address 101.aaa.bbb.1 255.255.255.0interface GigabitEthernet0/0/0/0.905 ipv4 point-to-point ipv4 unnumbered Loopback2000 service-policy type control subscriber IP_PM encapsulation dot1q 905 ipsubscriber ipv4 l2-connected  initiator dhcp  initiator unclassified-source  dynamic-template type ipsubscriber IPSUB_TPL  ipv4 unnumbered Loopback2000 !!class-map type control subscriber match-any IP_SUB match protocol dhcpv4 dhcpv6 end-class-map!policy-map type control subscriber IP_PM event session-start match-first  class type control subscriber IP_SUB do-all   10 activate dynamic-template IPSUB_TPL   20 authorize aaa list author_grp format USERNAME_FORMAT password iosxr  ! ! event account-logon match-first  class type control subscriber IP_SUB do-all   10 authenticate aaa list default  ! ! end-policy-map#Radius Status#show radius Tue Jan  7 09:56:52.137 GMTGlobal dead time: 0 minute(s)Number of Servers:1Server: 202.xx.xx.60/1645/1646  is UP  Total Deadtime: 0s Last Deadtime: 0s   Timeout: 10 sec, Retransmit limit: 3  Quarantined: No   Authentication:    11 requests, 1 pending, 31 retransmits    0 accepts, 0 rejects, 0 challenges    41 timeouts, 0 bad responses, 0 bad authenticators    0 unknown types, 0 dropped, 0 ms latest rtt    Throttled: 0 transactions, 0 timeout, 0 failures    Estimated Throttled Access Transactions: 0     Maximum Throttled Access Transactions: 0     Automated TEST Stats:        0 requests, 0 timeouts, 0 response, 0 pending  Accounting:    0 requests, 0 pending, 0 retransmits    0 responses, 0 timeouts, 0 bad responses    0 bad authenticators, 0 unknown types, 0 dropped    0 ms latest rtt    Throttled: 0 transactions, 0 timeout, 0 failures    Estimated Throttled Accounting Transactions: 0     Maximum Throttled Accounting Transactions: 0    Automated TEST Stats:        0 requests, 0 timeouts, 0 response, 0 pending

  • Assignment of Class to Vendor automatically

    I've got a requirement where any vendor that I create needs to have a class assigned to it during creation. Is this possible ? If it is possible, how can it be done ?
    Thanks in advance.

    Thanks for your reply guys.
    I know that we can assign a vendor class during creation of vendor master.
    But, I would like to know if there's any way to have a vendor class automatically assigned to an account group (or something) so that when I create a vendor master, the class shows up in the classification screen automatically.
    Appreciate your time and help.

  • ISE 1.2 - Multiple NICs/Load Balancing for DHCP Probe

    Hello guys
    Just prepping an ISE 1.2 patch 8 setup in our organization. I am going for the virtual appliances with multiple NICs. It will be a distributed deployment with 4 x PSNs behind a load balancer and there is no requirement for wireless or guest user at the moment. I've got 2 points I will like to get some guidance on:
    Our DC has a dedicated mgmt network and I plan to IP the gig0 interface of the PANs, MNTs and PSNs from this subnet. All device admin, clustering, config replication, etc will be over this interface. However, RADIUS/probe/other user traffic to the ISE PSNs will be over the gig1 interface which will be addressed from another L3 network. Is this a supported configuration in ISE?
    I intend to use the DHCP probe as part of device profiling and will ideally like to have just an additional ip helper to add to our switch SVI config. Also, it will appear that WLCs can only be configured for 2 DHCP servers for a given network so another consideration for when we bringing our WLAN in scope. We however use ACE load balancers within our DC and from what I have read, they do not support DHCP load balancing. Are there any workarounds to using the DHCP probe with multiple PSNs without having to add each node as an ip helper/DHCP server on the NADs?
    Thanks in advance
    Sayre

    Hello Sayre-
    For Question #1:
    Management is restricted to GigabitEthernet 0 and that cannot be changed so you should be good there
    You can configure Radius and Profiling to be enabled on other interfaces
    Even though you are not using guest services yet, you can dedicate an interface just for that. As a result, you can separate guest traffic completely from your production network
    Take a look at this link for more info:
    http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/installation_guide/ise_ig/ise_app_c-ports.html
    For Question #2
    If you are using a Cisco WLC and running code 7.4 and newer you don't need to mess with the IP helper configurations. 
    The controller can be configured to act as a collector for client profiling and interact with the DHCP thread along with the RADIUS accounting task that is running on the controller. The controller receives a copy of the DHCP request packet sent from the DHCP thread and parses the DHCP packet for two options:
    –Option 12—HostName of the client
    –Option 60—The Vendor Class Identifier
    After this information is gathered from the DHCP_REQUEST packet, a message is formed by the controller with these option fields and is sent to the RADIUS accounting thread, which is in turn transmitted to the ISE in the form of an interim accounting message.
    Both DHCP and HTTP profiling settings are located under the "Advanced" configuration tab in the WLC
    On the other hand, you can also use Anycast for profiling. You can check out some of Cisco Live's sessions for more info on that. Here is one that is from a couple of years (There are more recent ones that are available as well):
    http://www.alcatron.net/Cisco%20Live%202013%20Melbourne/Cisco%20Live%20Content/Security/BRKSEC-3040%20%20Advanced%20ISE%20and%20Secure%20Access%20Deployment.pdf
    I hope this helps!
    Thank you for rating helpful posts!

Maybe you are looking for

  • Endeca : multi invoice pay throwing correct error for internal user but it is failing to throw the same error for external user

    Hi, 1) Internal User expected exception: Exception: Payments,apply credits,disputes and print are not supported when multiple customer/currency transactions are selected 2) External User is throwing below error instead of throwing above exception. Er

  • Simple question about code

    Hello, I am beginning with SQL again after a long break and am having a niggling problem with the following code. What is going wrong? Thanks, Jonathon Sunny CREATE TABLE CHILDREN CHILD_ID INT NOT NULL PRIMARY KEY, FNAME VARCHAR(24) NOT NULL, LNAME V

  • How to Open multiple form with only one screen painter file

    Hi all , I want to reopen the form without closing the active form ,i want to use same srf file .. I have already try it but form already exist error occur . pl help me , how to do it ? how to open multiple form with same srf file without closing act

  • Downloading attachment file

    Downloading attachment file on my Nokia Lumia 1520 is not possible...can someone help me please...thank you.

  • Getting static constants of a class

    hi I have this class: package cl.mejorencasa.pedido.modelos      public class Pedido implements IPedido         public static const     ENESPERA:String   = "En Espera";         public static const     ATENDIENDO:String   = "Atendiendo";         publi