Controller Based WLANs

 View Only
last person joined: one year ago 

APs, Controllers, VIA

How does Role based Vlan work in Aruba OS 6.3? 

Sep 19, 2014 09:00 AM

Environment : This article applies to Aruba OS 6.3

 

Answer :

 

From AOS 6.3.0.0 to AOS 6.3.1.6, Role based vlan doesn't work in 802.1x authentication.

Pre AOS 6.3, where vlan mapped to the user-role does take effect and users are placed in the vlan mapped to the role. After upgrading to AOS 6.3, role based vlan are not honored in the 802.1x authentication.

Workaround : For 802.1x authentication, configure standard radius attribute in the authentication server and create a server rule in the controller to assign vlan. This doesn't work for default machine role and default user role as SDR will kick in only if the client passes both machine authentication and user authentication.

This workaround doesn't help when enforce machine is enabled in the controller or when a user entry existed, user entry was assigned to mac-auth derived role-based VLAN, and the client re-associated. A user was assigned to the default VLAN instead of the mac-auth derived role-based VLAN because mac-auth was skipped for the existing mac authenticated user-entry.

Starting from AOS 6.1.3.7, Role based vlan's are honored and users are placed in the vlan mapped to the user-role.

Statistics
0 Favorited
0 Views
0 Files
0 Shares
0 Downloads

Related Entries and Links

No Related Resource entered.