Your RADIUS config file passes back Tunnel-Private-Group-ID with the VLAN. Click on Authentication > Server Group > <server group assigned to the WPA2/AES SSID you are using>. Under the Server Rules section, click Add, then select Tunnel-Private-Group-ID from the Attribute drop down box, value-of from the Operation drop down and Set VLAN from the Action drop down. Then, click Add. Make sure the rule looks right to you and then click Apply at the bottom of the page (if you don't do this, it won't be saved).