Dell PowerConnect W-IAP92 Dell Instant 6.1.3.1-3.0.0.0 User Guide - Page 123

User VLAN Derivation, Vendor Specific Attributes (VSA)

Page 123 highlights

Chapter 11 User VLAN Derivation User VLAN Derivation Instant allows you to assign user VLAN through user attributes. When external RADIUS authentication server is used for authentication, the user VLAN can be derived from Vendor Specific Attributes (VSA). The user VLAN can be derived in 802.1x authentication or MAC authentication from the following rules:  Vendor Specific Attributes (VSA)  VLAN derivation rule  User role  SSID Profile The user VLAN cannot be derived in the following scenarios:  Captive Portal authentication  Guest SSID network Vendor Specific Attributes (VSA) When an external radius server is used, the user VLAN can be derived from the Dell-User-Vlan VSA.The VSA is then carried in Access-Accept packet from the radius server. The IAP can analyze the return message and get the value as VLAN to assign the user. Figure 97 Radius Access-Accept packets with VSA Dell PowerConnect W-Series Instant Access Point 6.1.3.1-3.0.0.0 | User Guide User VLAN Derivation | 123

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214

Dell PowerConnect W-Series Instant Access Point 6.1.3.1-3.0.0.0
|
User Guide
User VLAN Derivation
|
123
Chapter 11
User VLAN Derivation
User VLAN Derivation
Instant allows you to assign user VLAN through user attributes. When external RADIUS authentication server is
used for authentication, the user VLAN can be derived from Vendor Specific Attributes (VSA).
The user VLAN can be derived in 802.1x authentication or MAC authentication from the following rules:
Vendor Specific Attributes (VSA)
VLAN derivation rule
User role
SSID Profile
The user VLAN cannot be derived in the following scenarios:
Captive Portal authentication
Guest SSID network
Vendor Specific Attributes (VSA)
When an external radius server is used, the user VLAN can be derived from the
Dell-User-Vlan
VSA.The VSA is
then carried in Access-Accept packet from the radius server. The IAP can analyze the return message and get the
value as VLAN to assign the user.
Figure 97
Radius Access—Accept packets with VSA