07-07-2021 01:12 PM
I have a two WING controllers (VM appliances) configured as a cluster.
The controllers are configured as radius client in EAC
The WLAN I connect to, must do a MAC address athentication. So far its works. But the client isn't placed in the right vlan.
How can I achieve a radius overwrite of the vlan.
Solved! Go to Solution.
07-15-2021 10:16 AM
Hi Johan,
It seems there’s no VLAN ID set in the Policy Mapping that is chosen for a given NAC Profile.
Please see here, “VLAN [ID] Name” value has to be set:
Hope that helps,
Tomasz
07-15-2021 01:54 PM
Tomasz,
Check. this was the solution.
07-15-2021 10:16 AM
Hi Johan,
It seems there’s no VLAN ID set in the Policy Mapping that is chosen for a given NAC Profile.
Please see here, “VLAN [ID] Name” value has to be set:
Hope that helps,
Tomasz
07-15-2021 06:16 AM
Thomasz,
Device is set to Radius attributes to send on RFC 3580 - VLAN ID
I see only 2 attributes..
Tunnel-Private-Group-Id isn't set.
07-13-2021 01:20 PM
Hi Johan,
For dynamic VLAN assignment you want the EAC to send the attributes like this (you can verify by highlighting your end-system row under Authorization column):
I mean, the ‘Tunnel-’ trio.
This can be chosen under Switches tab within EAC configuration (RADIUS Attributes To Send):
If this is set (and device is granted relevant EAC Profile and ‘Accept Policy’ - which is a policy mapping in fact) you should see appropriate Tunnel attributes being sent as your End-System table indicates.
Then, if your devices are still not getting their VLAN, it might be something along the way or WiNG config itself. But I’d review that part first.
Hope that helps,
Tomasz