====== HOW DO I ASSIGN DIFFERENT VLANS TO THE SAME WLAN/SSID ====== ===== Objetive ===== * How do I assign different vlans to the same WLAN/SSID * Dynamic VLAN assignment to one SSID; “RFC 3580 (ACCESS-ACCEPT) Options” * Assigning dynamic role by using Tunnel-Private-Group-ID * 802.1x ===== Environment ===== IdentiFi Wireless ===== Procedure ===== To assign different VLANs to the same SSID, the VLAN must first be configured on the Switch’s the APs are connect to for “B@AP topology” or the switch the Controller is connected to for “B@WC topology”. This document will focus on VLAN 217. * A WLAN Service is configured with a Default Topology, (in this example, the Default Topology is Vlan216), with “Auth & Acct” Authentication Mode 802.1x. {{:extreme_networks:controller:assign_different_vlans_to_the_same_wlanssid_1_-_hvillanueva.jpg?600|}} {{:extreme_networks:controller:assign_different_vlans_to_the_same_wlanssid_2_-_hvillanueva.jpg?600|}} * A roll needs to be configured for each VLAN. {{:extreme_networks:controller:assign_different_vlans_to_the_same_wlanssid_3_-_hvillanueva.jpg?600|}} * The VLAN mapping must be configured under the RADIUS setting. * “VNS>Global>Authentication>(radius)>RFC 3580 (ACCESS-ACCEPT) Option * Select “Both RADIUS Filter-ID and Tunnel-Private Group-ID attributes” * Click “New” * Enter a name * Select Role from drop-down. * Click Add * Click Save {{:extreme_networks:controller:assign_different_vlans_to_the_same_wlanssid_4_-_hvillanueva.jpg?600|}} **TEST:** Using WireShark, confirm Radius returns correct AVP with correct VLAN ID. {{:extreme_networks:controller:assign_different_vlans_to_the_same_wlanssid_5_-_hvillanueva.jpg?600|}} Confirm using Controllers “Report by Clients” that end Device is in correct VLAN {{:extreme_networks:controller:assign_different_vlans_to_the_same_wlanssid_6_-_hvillanueva.jpg?600|}} --- //[[ing.hvillanueva@gmail.com|Humberto Villanueva]] 2020/12/01 14:08//