Does anyone know if it is possible to use dynamic VLAN assignment with ClearPass for a RAP virtual-ap profile in split-tunnel mode?
Example VAP config:
wlan virtual-ap "CORP_RAP"
aaa-profile "CORP_aaa_prof"
vlan 999
forward-mode split-tunnel
ssid-profile "CORP_RAP_ssid_prof"
broadcast-filter all
!
user-role A
access-list session allowall
vlan 111
!
user-role B
access-list session allowall
vlan 222
ClearPass would return role A or B which sets a different VLAN.
The documentation says named VLANs and VLAN pooling aren't allowed with split-tunnel mode + RAP, but can't see anything to say this wouldn't work?