Wireless Access

last person joined: 22 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

One SSID and multiple VLANs

This thread has been viewed 18 times
  • 1.  One SSID and multiple VLANs

    Posted Sep 10, 2014 10:46 AM

    Hi,

    Is it possible to have one SSID and direct the user to different VLANs based on the return of Radius authentication?

    I'm using the bridge mode configuration.



  • 2.  RE: One SSID and multiple VLANs

    Posted Sep 10, 2014 11:19 AM

    Yes you can , what radius server are you using ?



  • 3.  RE: One SSID and multiple VLANs

    Posted Sep 10, 2014 11:22 AM

    We use Microsoft NPS server and 802.1x authentication (EAP-TLS).



  • 4.  RE: One SSID and multiple VLANs
    Best Answer

    Posted Sep 10, 2014 11:47 AM
      |   view attached

    2014-09-10 11_45_38-Switch General Configuration.png

    And in the NPS policy you can speficy the filter-id you want to send back

     

    2014i195D23B4462E0FDA.jpg

     

     

    Attachment(s)



  • 5.  RE: One SSID and multiple VLANs

    Posted Sep 10, 2014 11:50 AM

    Thank you Victor.

    We will try this.



  • 6.  RE: One SSID and multiple VLANs

    Posted Sep 10, 2014 12:10 PM

    One more question.

    If I create the server rules to set the correct vlan, do I need to set the vlan at the Virtual AP configuration?



  • 7.  RE: One SSID and multiple VLANs

    Posted Sep 10, 2014 12:15 PM

    Unless you want to authenticated user that's not included in the server rules to get a default (VLAN) then you don't. 



  • 8.  RE: One SSID and multiple VLANs

    Posted Feb 20, 2015 12:49 PM

    If I set at NPS a rule with an attribute as this:

    Name: Vendor-Specific

    Attribute number: 26

    Vendor Code: 14823

    Vendor assigned attribute number: 2

    Atribute format: Decimal

    Atribute value: 64

    Do I need to create a server rule with the same attributes at the server group profile on controller?like this: set vlan condition Class equals "64" set-value 64