Dell PowerConnect W-IAP92 Dell Instant 6.2.0.0-3.2.0.0 User Guide - Page 149

User VLAN Derivation, Vendor Specific Attributes (VSA)

Page 149 highlights

Chapter 13 User VLAN Derivation User VLAN Derivation W-Instant allows you to assign a user VLAN based on user attributes. When an external RADIUS authentication server is used for authentication, the user VLAN can be derived from Vendor Specific Attributes (VSAs). The user VLAN can be derived in 802.1X authentication or MAC authentication using the following rules: l Vendor Specific Attributes (VSA) l VLAN derivation rule l User role l SSID Profile The user VLAN cannot be derived in the following scenarios: l Captive Portal authentication l Guest SSID network Vendor Specific Attributes (VSA) When an external RADIUS server is used, the user VLAN can be derived from the Dell-User-Vlan VSA. The VSA is then carried in an Access-Accept packet from the RADIUS server. The W-IAP can analyze the return message and derive the value of the VLAN which it assigns to the user. Figure 108 - RADIUS Access-Accept packets with VSA Dell PowerConnect W-Series Instant Access Point 6.2.0.0-3.2.0.0 | User Guide 149 | User VLAN Derivation

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296

Dell PowerConnect W-Series Instant Access Point
6.2.0.0-3.2.0.0
|
User Guide
149
|
User VLAN Derivation
Chapter 13
User VLAN Derivation
User VLAN Derivation
W-Instant allows you to assign a user VLAN based on user attributes. When an external RADIUS
authentication server is used for authentication, the user VLAN can be derived from Vendor
Specific Attributes (VSAs).
The user VLAN can be derived in 802.1X authentication or MAC authentication using the
following rules:
l
Vendor Specific Attributes (VSA)
l
VLAN derivation rule
l
User role
l
SSID Profile
The user VLAN cannot be derived in the following scenarios:
l
Captive Portal authentication
l
Guest SSID network
Vendor Specific Attributes (VSA)
When an external RADIUS server is used, the user VLAN can be derived from the
Dell-User-Vlan
VSA. The VSA is then carried in an Access-Accept packet from the RADIUS server. The W-IAP
can analyze the return message and derive the value of the VLAN which it assigns to the user.
Figure 108
- RADIUS Access—Accept packets with VSA