- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SSID Tunneling Supported Security and VLAN Tagging Methods
- Enterprise Authentication with Radius Server (NPS) doing VLAN association
- IPSK without Radius doing VLAN tagging on a group policy?
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Andrew I can answer the IPSK question. I just tested and the client does indeed honor the VLAN sent in the Group Policy when using IPSK. I would imagine a VLAN sent via RADIUS would also work fine.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Take a look at the documentation.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @alemabrahao thanks for your help.
I have reviewed the documentation and I know it infers that Radius authentication works with VPN concentrator mode but I'd like to confirm with the experience of others that there are no issues with honoring the VLAN from the Radius server.
Additionally it doesn't mention IPSK without Radius and VLAN tagging through a group policy so I'm seeking clarification there as well.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can perform a LAB to confirm. 😉
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If I had that option perhaps I wouldn't have posted on this forum asking for clarification 😉
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Andrew I can answer the IPSK question. I just tested and the client does indeed honor the VLAN sent in the Group Policy when using IPSK. I would imagine a VLAN sent via RADIUS would also work fine.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FANTASTIC! Thanks Ryan! You're awesome and I really appreciate you testing it in such a short time.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just tested using JumpCloud RADIUS and the VLAN attribute is also honored/working.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks again Ryan.
Just to confirm, for the Client and VLAN settings on the SSID we're leaving the VLAN tag unselected right?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In my lab the MX is concentrator mode. So not a interface dropdown, but rather an open field to type a non default/native VLAN ID. But I don't think the behavior would be any different.
In my usual setup I have the tunneled SSID drop clients into VLAN 600 (a DMZ subnet).
In my testing this morning I added VLAN 90 to the switchport connected to my MX. Then for the IPSK and RADIUS tests I set VLAN 90 as the VLAN tag (IPSK) /Tunnel-Private-Group-ID attribute (RADIUS). For the RADIUS config you of course need to enable the toggle for RADIUS override for the VLAN tagging to work.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Perfect. Thanks Ryan you're a godsend!
