VLANS & Mobile devices roaming 50

syedjahanzaib Lv1Posted 12 Dec 2022 11:40

Last edited by syedjahanzaib 12 Dec 2022 12:48.

In our company we Active directory/dhcp running on single default VLAN1 with /8 DHCP pool (yes /8 is bad & we are trying to get rid of by /8 introducing vlans & different ip subnet scheme for each Dept.). Laptop/Desktop users gets ip from 10.0.0.1-10.0.10.255 pool which is set for SSO AD Authentication in IAM. For mobiles phones devices we manualy reserve there ip ip from 10.0.11.1-10.0.11.255 pool & in sangfor we added this 2nd pool in auth policy for local account (USER MAC address local Account in IAM). so in in order to allow internet for mobile phone devices, we only reserve his mobile mac address in dhcp to get ip from 10.10.11.x series gateway pointint got IAM device & his interent works automatically. We also have wifi (UBNT APs) across the company with single SSID so that users internet should work transparently at any location.



We are in process of introducing vlans/subnet for each Dept. Desktop laptop gets whatever IP there internet works fine via SSO AD auth, BUT how mobile devices will going to work if they roam around & gets different ip series from roamed vlan.

Example if set to do SSO auth on 10.0.0.1-10.0.0.100 , & 10.0.0.101-10.0.0.200 for local mac auth, (VLAN-10 dhcp range) We just reserve the user mobile mac address to use the later range (local mac account) & users mobiel internet works fine, BUT if the user mobile roams around to vlan-11 Dept. where he dont have the mac reservation in dhcp for vlan-11 pool, his internet will not work because he will by default get ip vlan-11 pool  which auth will work via SSO & mobile internet will not work auto.

so if I have 50 VLANs, do I have to reserve mobile ip in all 50 vlan later range for mac auth, not possible. what is the workaround?

Farina Ahmed has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins, 50 coins of bounty and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Binding MAC Addresses of each mobile is the only best solution. Otherwise you will always have this problem in future of associating certain IPs to certain devices.
Is this answer helpful?
RegiBoy Lv5Posted 13 Dec 2022 08:35
  
try to bind the mac-address to a fixed IP.
Usman Aslam Lv1Posted 13 Dec 2022 21:18
  
Try this command ipconfig /flushdns.
syedjahanzaib Lv1Posted 14 Dec 2022 01:39
  
Last edited by syedjahanzaib 14 Dec 2022 18:21.

If I bind MAC>IP, what will happen when the user will roam from one vlan to other vlan and at other vlan he will get ip from other vlan pool. How many reservations I have to make if I have 50 + vlans ? so kindly read the query again.

Let me redefine the query again.

to allow users mobile devices, we assign them ip from DHCP using specific pool like 192.168.1.0/24, then we create there local user account under in Sangfor "Acess management > Users Binding Mgt >  User Binding" . Also in Auth Policy, I have added policy on top that if user request is coming from this 92.168.10/24 pool then use Local User Databses (as shown in the pictures attached).

This way when they access internet without any authentication.

I am now introducing VLANS/subnets for for every department. every department will have many phones. I cannot reserve there ips in particular pool as every dept will have different vlan pool, and users also roams between many depts all day. I cannot reseve there ip in each vlan pool.

Is there any way that no matter what ip pool user is coming from , & IF he have account (mac address) is added in "acess management > Users Binding Mgt >  User Binding", his internet should work Directly?

With Users Binding m I can have its proper name so that I can have his log by name as well and also monitoring is easy by username. Whats the workaround for it?

4 user binding.png (77.79 KB, Downloads: 413)

4 user binding.png

2.PNG (20.88 KB, Downloads: 412)

2.PNG

3.PNG (17.04 KB, Downloads: 418)

3.PNG

1.PNG (11.65 KB, Downloads: 413)

1.PNG
LucyHeart Lv3Posted 16 Dec 2022 13:58
  
create another ssid and that ssid will be vlan 10
Happpy Lv3Posted 16 Dec 2022 14:19
  
Is this resolve? following this thread.
Naomi Lv3Posted 18 Dec 2022 13:54
  
You may try to flush the configured DNS.
Robin Lv3Posted 18 Dec 2022 14:03
  
No there is none.
rivsy Lv5Posted 19 Dec 2022 08:02
  
Did you check if the IP Bunding is properly configure with both ends?
Farina Ahmed Lv5Posted 19 Dec 2022 13:20
  
Binding MAC Addresses of each mobile is the only best solution. Otherwise you will always have this problem in future of associating certain IPs to certain devices.

I Can Help:

Change

Moderator on This Board

11
54
1

Started Topics

Followers

Follow

15
21
3

Started Topics

Followers

Follow

Board Leaders