Hello all, I've got a two controller setup currently, with one in the office, and one at our data centre. The office controller has two SSIDs: one for corporate, which puts the traffic on the local network, and one for guest Internet access, which tunnels the traffic down to the data centre controller and goes out to the Internet from there. It uses Captive Portal with internal accounts for guest access. I'd like to add another SSID for corporate users phones, which would also tunnel to the data centre and allow them to access the Internet from there, also through Captive Portal, but with RADIUS auth instead of internal. There will also be different firewall policies applied, so it definitely needs to be a different VLAN and SSID. I've set up the new corporate SSID in the office, and I can see the traffic tunneling down to the data centre, but the user is getting the guest access user role, rather than the corporate user role. I can't seem to find where I tell it that when access is coming from the guest VLAN or SSID, to use the guest role, and when it's coming from the corporate VLAN or SSID, to use the corporate role. Can anyone advise? Cheers, John Moe