Hi Yury,
Firstly, I have to confess that I could not understand how to configure the first method on the wireless controller. Because as I know, a VNS can only bind a WLAN service to only two different Roles (non-authenticated / authenticated).
Anyway, I tried my best and deleted all custom made CoS and Roles on the EWC, then enforced domain policies from Netsight successfully. Then I configured the VNS as below:
![167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-84620-1jv9982-8021x_inline.jpg 167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-84620-1jv9982-8021x_inline.jpg](/t5/image/serverpage/image-id/944iB41A4999DDE1B98B/image-size/large?v=v2&px=999)
Then, I tested this configuration by connecting two different clients to the same SSID (test-8021x) simultaneously: one of the clients assigned to "Vlan211" and the other assigned to "Vlan311" which are not related to "NOT_Domain_PC" role. They are just assigned to Vlans that NAC sends as radius attributes :
Test client-1 Authentication session:
![167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-55200-tl5rc-8021x-2_inline.png 167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-55200-tl5rc-8021x-2_inline.png](/t5/image/serverpage/image-id/1418i87807B6B9EEB2077/image-size/large?v=v2&px=999)
Test client-2 Authentication session:
![167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-128099-8uj7eu-8021x-3_inline.png 167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-128099-8uj7eu-8021x-3_inline.png](/t5/image/serverpage/image-id/2888iE875DEE596FEAD36/image-size/large?v=v2&px=999)
I understand from this test that no matter what is chosen in the "Default Roles >> Authenticated" field, clients are assigned according to radius attribute that NAC sends.
Is it right ?
Thanks