Hi sdr,
I'm picking up what you're putting down - so I'm not sure what I'm missing.
The workflow for your services is something similar:
1. User connects to an open SSID and gets placed into a Captive Portal. The user will currently have VLAN X
2. The user logs into the form on the Captive Portal and the pre-auth service authenticates their request
3. The user is then serviced by the Guest and MAC Caching service where a custom attribute is set and they are sent an Aruba Terminate Session CoA
4. The user is disconnected from the network
5. The user reconnects to the same SSID and performs a MAC Authentication.
6. As part of your enforcement profile, you send them a RADIUS VSA of an VLAN
7. The user is now in VLAN Y based on step 6
Does that sound right?
Thanks!
-Mike