Assign Vlan on MAC Netlogin with Freeradius

  • 22 September 2015
  • 6 replies

I'm running on MAC Netlogin Authentication with Freeradius. BTW, I got a problem on Vlan after

authenticated. The Vlan can't be assigned to authenticated user as define in "user" file on

Freeradius. My configuration as below:

--- Switch SummitX 430 ---
unconfigure switch all
configure Defaut delete port all
create vlan Data tag 10
concfigure Data ipaddress
concfigure Data add port 1,2 untage <---port 1 connected to Freeradius
create vlan Voice tag 20
configure netlogin vlan Voice
enable netlogin mac
configure netlogin mac authentication database-order radius
configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48 port 2
enable netlogin ports 2 mac
configure netlogin ports 2 mode port-based-vlans
configure radius netlogin primary server client-ip vr vr-default
configure radius netlogin primary shared-secret mysecret
enable radius netlogin

--- Users file on Freeradius ---

0016ECBDA167 Cleartext-Password := 0016ECBDA167
Extreme-Netlogin-VLAN = UVoice,
Extreme-Netlogin-Extended-VLAN = UVoice,

--- Client.conf file on Freeradius ---

client Dist1 {
ipaddr =
secret = mysecret
require_message_authenticator = no
nastype = other

--------Log and Result-----------
Sending Access-Accept of id 58 to port 32769
Extreme-Netlogin-Vlan = "UVoice"
Extreme-Netlogin-Extended-Vlan = "UVoice"

Questions :
1. Why the user can't be assigned to Vlan Voice, any thing wrong on User attributes?
2. I try "configure radius netlogin primary server client-ip" then got

error "IP address is not configured in virtual router "VR-Mgmt" for server Primary

Net-Login" then I tried vr-default it work, is this the cause for the above problem?

Thank you

6 replies

Userlevel 6
Hi Muhammad,

The error message which you have got is a expected one and that should not be the cause of the issue.

Can you try only with Extreme-Netlogin-Extended-Vlan = "UVoice" and see if it works?

Thank you for your reply

but still Not work

The log on Freeradius show that "Access-Accept" but I set up the PC ip then ping to, it's unreachable. Does the port will be shown on the Vlan?

* Dist1.1 # sh "Voice"VLAN Interface with name Voice created by user
Admin State: Enabled Tagging: 802.1Q Tag 20
Description: None
Virtual router: VR-Default
IPv4 Forwarding: Disabled
IPv4 MC Forwarding: Disabled
Primary IP:
IPv6 Forwarding: Disabled
IPv6 MC Forwarding: Disabled
IPv6: None
STPD: None
Protocol: Match all unfiltered protocols
Loopback: Enabled
NetLogin: Enabled
OpenFlow: Disabled
TRILL: Disabled
QosProfile: None configured
Egress Rate Limit Designated Port: None configured
Flood Rate Limit QosProfile: None configured
Ports: 0. (Number of active ports=0)

Userlevel 6
Hi Muhammad,

Thank you for trying the suggestion. When the port is successfully added to the dynamic VLAN, it should be shown in the show vlan output.

If the port 2 is the client connected port, can you try to remove it from the vlan data and check if that works.

concfigure Data add port 1,2 untage

As per this config, it is added as untagged in the vlan data

Great !!!
now port 2 show on vlan Voice, but still can't ping the interface, I will try to solve that (might easy.. hopefully).

another issue is that I want to add difference vlan to each user as
user1 = vlan Voice
user2 = vlan Office
user3 = vlan staff

it can define on user file, but on switch do I have to configure anything more?
at the begin I configure netlogin voice only

configure netlogin vlan Voice

when I try to add new vlan, it show only the last added vlan
Userlevel 6
Thats great!

I just noticed in the configuration that the Voice is added as a netlogin VLAN. The netlogin should be a temporary VLAN which is used only for the netlogin purpose.

it is recommended that we do not use any of the data VLAN as a netlogin VLAN.

The following article could help you get with the basic configuration for netlogin.

So, lets say you are using temp vlan as the netlogin vlan. it will be used for the authentication. Once the user is authenticated, based on the VSA from the free-radius, the dynamic VLAN will be assigned.

So, no additional configuration is needed.

Hope this helps!!
Job done !! thank you for your great solution
really nice impression for my first post