D-Link DWL-8500AP Product Manual - Page 123

Tunnel-Type=VLAN 13, Tunnel-Private-Group-ID=VLANID

Page 123 highlights

A Wireless Client Settings and RADIUS Server Setup valid, the NAS configures the port to the VLAN indicated by the RADIUS authentication server. A RADIUS server needs to be configured to use Tunnel attributes in Access-Accept messages, in order to inform the access point about the selected VLAN. These attributes are defined in RFC 2868 and their use for dynamic VLAN is specified in RFC 3580. If you use an external RADIUS server to manage VLANs, the server must use the following VLAN attributes (as defined in RFC3580): • Tunnel-Type=VLAN (13) • Tunnel-Medium-Type=802 • Tunnel-Private-Group-ID=VLANID In the case of FreeRADIUS server, the following options may be set in the users file to add the necessary attributes. example-user Auth-Type :=EAP, User-Password =="nopassword" Tunnel-Type = 13, Tunnel-Medium-Type = 802, Tunnel-Private-Group-ID = 7 Tunnel-Type and Tunnel-Medium-Type use the same values for all stations. Tunnel-PrivateGroup-ID is the selected VLAN ID and can be different for each user. NOTE: Do not use the management VLAN ID for the value of the Tunnel-Private- Group-ID. The dynamically-assigned RADIUS VLAN cannot be the same as the management VLAN. If the RADIUS server attempts to assign a dynamic VLAN that is also the management VLAN, the AP ignores the dynamic VLAN assignment, and a newly associated client is assigned to the default VLAN for that VAP. A re-authenticating client retains its previous VLAN ID. Configuring the RADIUS Server for VLAN Tags 123

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168

Configuring the RADIUS Server for VLAN Tags
123
A
Wireless Client Settings and RADIUS Server Setup
valid, the NAS configures the port to the VLAN indicated by the RADIUS authentication
server.
A RADIUS server needs to be configured to use Tunnel attributes in Access-Accept messages,
in order to inform the access point about the selected VLAN. These attributes are defined in
RFC 2868 and their use for dynamic VLAN is specified in RFC 3580.
If you use an external RADIUS server to manage VLANs, the server must use the following
VLAN attributes (as defined in RFC3580):
Tunnel-Type=VLAN (13)
Tunnel-Medium-Type=802
Tunnel-Private-Group-ID=VLANID
In the case of FreeRADIUS server, the following options may be set in the users file to add the
necessary attributes.
example-user Auth-Type :=EAP, User-Password =="nopassword"
Tunnel-Type = 13,
Tunnel-Medium-Type = 802,
Tunnel-Private-Group-ID = 7
Tunnel-Type and Tunnel-Medium-Type use the same values for all stations. Tunnel-Private-
Group-ID is the selected VLAN ID and can be different for each user.
NOTE:
Do not use the management VLAN ID for the value of the Tunnel-Private-
Group-ID. The dynamically-assigned RADIUS VLAN cannot be the same as
the management VLAN. If the RADIUS server attempts to assign a dynamic
VLAN that is also the management VLAN, the AP ignores the dynamic
VLAN assignment, and a newly associated client is assigned to the default
VLAN for that VAP. A re-authenticating client retains its previous VLAN ID.