In the earlier versions of CX, similar to ArubaOS-Switches, the VLAN was defined in the role. Idea behind it (probably) is that you just need to return the role and don't need to bother about VLANs on your RADIUS/ClearPass.
In more recent versions, you now have the option to override the role VLAN (and some other attributes) with RADIUS.
Hope this helps to understand where this is coming from.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Jan 23, 2024 02:44 AM
From: Thomas Korndal
Subject: Aruba Central with Client Roles and dynamic VLAN assignment
This is both relating to Clearpass and Aruba Central.
When creating a role on Central is not possible without defining a VLAN.
But is that overwritten when using clearpass to assign a Local User Role. as I see it I need to both return the the role and a specific VLAN.