To assign different VLANs to the same SSID, the VLAN must first be configured on the Switch’s the APs are connect to for “B@AP topology” or the switch the Controller is connected to for “B@WC topology”. This document will focus on VLAN 217.
- A WLAN Service is configured with a Default Topology, (in this example, the Default Topology is Vlan216), with “Auth & Acct” Authentication Mode 802.1x.
- A roll needs to be configured for each VLAN.
- The VLAN mapping must be configured under the RADIUS setting.
TEST:Using WireShark, confirm Radius returns correct AVP with correct VLAN ID.
Confirm using Controllers “Report by Clients” that end Device is in correct VLAN (image6)
- “VNS>Global>Authentication>(radius)>RFC 3580 (ACCESS-ACCEPT) Option
- Select “Both RADIUS Filter-ID and Tunnel-Private Group-ID attributes”
- Click “New”
- Enter a name
- Select Role from drop-down.
- Click Add
- Click Save