ZyXEL NWA-3500 User Guide - Page 254

Configuring VLAN Groups

Page 254 highlights

Chapter 20 VLAN ZyXEL uses the following standard RADIUS attributes returned from Microsoft's IAS RADIUS service to place the wireless station into the correct VLAN: Table 79 Standard RADIUS Attributes ATTRIBUTE NAME TYPE Tunnel-Type 064 Tunnel-Medium-Type 065 Tunnel-Private- 081 Group-ID VALUE 13 (decimal) - VLAN 6 (decimal) - 802 (string) - either the Name you enter in the NWA's VLAN > RADIUS VLAN screen or the number. See Figure 155 on page 261. The following occurs under Dynamic VLAN Assignment: 1 When you configure your wireless credentials, the NWA sends the information to the IAS server using RADIUS protocol. 2 Authentication by the RADIUS server is successful. 3 The RADIUS server sends three attributes related to this feature. 4 The NWA compares these attributes with the VLAN screen mapping table. 4a If the Name, for example "VLAN 20" is found, the mapped VLAN ID is used. 4b If the Name is not found in the mapping table, the string in the TunnelPrivate-Group-ID attribute is considered as a number ID format, for example 2493. The range of the number ID (Name:string) is between 1 and 4094. 4c If a or b are not matched, the NWA uses the VLAN ID configured in the WIRELESS VLAN screen and the wireless station. This VLAN ID is independent and hence different to the ID in the VLAN screen. 20.3.3.1 Configuring VLAN Groups To configure a VLAN group you must first define the VLAN Groups on the Active Directory server and assign the user accounts to each VLAN Group. 1 Using the Active Directory Users and Computers administrative tool, create the VLAN Groups that will be used for each VLAN ID. One VLAN Group must be created for each VLAN defined on the NWA. The VLAN Groups must be created as Global/Security groups. 1a Type a name for the VLAN Group that describes the VLAN Group's function. 1b Select the Global Group scope parameter check box. 254 NWA-3500/NWA-3550 User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408

Chapter 20 VLAN
NWA-3500/NWA-3550 User’s Guide
254
ZyXEL uses the following standard RADIUS attributes returned from Microsoft’s
IAS RADIUS service to place the wireless station
into the correct VLAN:
The following occurs under Dynamic VLAN Assignment:
1
When you configure your wireless credentials, the NWA sends the information to
the IAS server using RADIUS protocol.
2
Authentication by the RADIUS server is successful.
3
The RADIUS server sends three attributes related to this feature.
4
The NWA compares these attributes with the VLAN screen mapping table.
4a
If the
Name
, for example “VLAN 20” is found, the mapped VLAN ID is used.
4b
If the
Name
is not found in the mapping table, the string in the
Tunnel-
Private-Group-ID
attribute is considered as a number ID format, for
example 2493. The range of the number ID (Name:string) is between 1 and
4094.
4c
If
a
or
b
are not matched, the NWA uses the VLAN ID configured in the
WIRELESS VLAN
screen and the wireless station. This
VLAN ID
is
independent and hence different to the
ID
in the VLAN screen.
20.3.3.1
Configuring VLAN Groups
To configure a VLAN group you must first define the VLAN Groups on the Active
Directory server and assign the user accounts to each VLAN Group.
1
Using the Active Directory Users and Computers administrative tool, create the
VLAN Groups that will be used for each VLAN ID. One VLAN Group must be
created for each VLAN defined on the NWA. The VLAN Groups must be created as
Global/Security groups.
1a
Type a name for the
VLAN Group
that describes the VLAN Group’s function.
1b
Select the
Global
Group scope parameter check box.
Table 79
Standard RADIUS Attributes
ATTRIBUTE NAME
TYPE
VALUE
Tunnel-Type
064
13 (decimal) – VLAN
Tunnel-Medium-Type 065
6 (decimal) – 802
Tunnel-Private-
Group-ID
081
<vlan-name> (string) – either the
Name
you enter in
the NWA’s
VLAN > RADIUS VLAN
screen or the
number. See
Figure 155 on page 261
.