02-28-2016 10:59 PM
I need to reconfigure all my ssid from bridge to tunnel mode because we need to have more control about the packets for a better troubleshooting. I have one question. is raidus accounting supported in tunnel mode (for vlan assignement? I suppose that the response is "yes" but i haven't find anything about it and i need to be sure before change all.
Solved! Go to Solution.
02-29-2016 12:55 AM
03-07-2016 03:15 AM - edited 03-07-2016 03:29 AM
Thanks. I supposed that should be valid. One question only. I have a few doubts about the configuration. Since the ssid is configured in tunnel mode, when I configure the vlan on it, I must set only de default vlan, isn't it? The vlan selected by the role in the radius will be changed later to the correct one and the vlan configured in the ssid will not be used. Is correct? or i have to configure all vlans that can be assigned by the radius?
03-07-2016 03:48 AM
You only need to set the "Default" VLAN in the Virtual AP profile. The default VLAN is the VLAN assigned to the client if no VLAN information is received in the radius response. Most clients will just authenticate successfully and be placed into this default VLAN. If you want clients to be placed into a different VLAN, you need to make sure that the controller has (1) the vlan created (2) the VLAN is trunked to the controller or assigned to an access port on the controller and (3) you send back an Aruba-User-VLAN radius attribute with that vlan. When you send back that attribute in the radius response, it will override the default VLAN defined.
Aruba Customer Engineering
Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base