Hi Friend,
Adding to the reply by Victor here are steps to configure the RAS policy for dynamic VLAN assignment.
Select New policy and give a name ( DemoPolicy)
![IAS1.JPG IAS1.JPG](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/cf285a88b3fc46ba869875d03b704366_618f34ca406e426f8dd2f8a297fcaa2b)
Select Wireless :
![IAS2.JPG IAS2.JPG](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/cf285a88b3fc46ba869875d03b704366_fd0dbb2ced1b4bea82ba2bda5be52473)
Select the user group to map this policy (Manager is a group)
![IAS3.JPG IAS3.JPG](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/cf285a88b3fc46ba869875d03b704366_ff179f77370b43cf8d89551ceee492cb)
Select Grant RAS and click on Edit profile
![ias4.JPG ias4.JPG](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/cf285a88b3fc46ba869875d03b704366_6df244b7ae3d4f149e7dfc649b8139a0)
Select Advanced Tab and select Add
![ias5.JPG ias5.JPG](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/cf285a88b3fc46ba869875d03b704366_b3fb99d8adb44ffdbe0f9a14bd8d70dd)
Select Attribute name as either Filterid or "Vendor specific". to make your life simple select "Vendor Specific" and click on Add.
![ias7.JPG ias7.JPG](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/cf285a88b3fc46ba869875d03b704366_07a3b58655f5477d9ab8bf4ed6c02f17)
Select option, "Enter Vendor-code" the value for Aruba is 14823
Select option "It Confirms" and select "Configure Attributes"
![ias9.JPG ias9.JPG](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/cf285a88b3fc46ba869875d03b704366_ce0076bce0e64648b8255c33cea798ea)
Select the appropriate value and type as shown bellow.
![ias8.JPG ias8.JPG](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/cf285a88b3fc46ba869875d03b704366_a8a7af5d55424f64b4debe687338eee5)
Here for returning VLAN id we should select attribute number as 2 and format as Integer (Decimal) and finally enter the vlan id as the Attribute value.
![ias10.JPG ias10.JPG](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/cf285a88b3fc46ba869875d03b704366_97f0d4cf114245bfaff4a98ba63d0f7d)
The server side configuration is done.
Now we should configure the server group to assign the return attribute ,
![ias11.JPG ias11.JPG](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/cf285a88b3fc46ba869875d03b704366_e1d70c84ec2d45c88dc62c6d6127d046)
Another way is, map a VLAN to the user role and configure the IAS to return the role name
How to map a VLAN to a Role:
![ias12.JPG ias12.JPG](https://higherlogicdownload.s3.amazonaws.com/HPE/MigratedInlineFiles/cf285a88b3fc46ba869875d03b704366_4bfb67a69cbf4baea3d27c4f81eb2a8d)
Hope got more clarity,
Please feel free for any further help on this,
Have fun with Aruba :)