<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello, William in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/aaa-vlan-assignment-per-flexgroup-with-vlan-name/m-p/3018430#M143921</link>
    <description>&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hello,&amp;nbsp;William&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"Sounds like your Radius server is returning the attribute but your AP may not be aware of the VLAN in question."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The VLAN is configured on the AP via FlexConnect Group. Also FlexConnect VLAN Template is configured.&lt;/P&gt;
&lt;P&gt;The problem only exists, when RADIUS server is configured to return VLAN NAME instead of VLAN ID and when AP is on FlexConnect mode with Central Switching (in this case AAA override works with VLAN NAME), but when the AP lost connection to the WLC (and starts to authenticate locally), then the AP is not aware of the VLAN name to ID mapping, therefore it puts the client on the default VLAN.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;These errors are shown, when AP is joining to the FlexConnect Group initially, configured with FlexConnect VLAN Template. I&amp;nbsp;think this is the main reason, AP not to be aware of VLAN name to ID mapping, therefore it can't override the VLAN when authenticate users&amp;nbsp;by itself (Local Auth).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We use&amp;nbsp;VLAN IDs, instead of VLAN NAMES for '&lt;SPAN&gt;Tunnel-Private-Group-ID' attribute&lt;/SPAN&gt;&amp;nbsp;as workaround for this issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TLV-DEC-ERR: can not process TLV for TLV_FLEX_VLAN_NAME_ID_MAPPING_PAYLOAD (591/0)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;TLV-DEC-ERR: No CB for TLV_FLEX_VLAN_NAME_ID_MAPPING_PAYLOAD (591)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jun 2017 09:26:33 GMT</pubDate>
    <dc:creator>smartitbg</dc:creator>
    <dc:date>2017-06-20T09:26:33Z</dc:date>
    <item>
      <title>AAA VLAN assignment per FlexGroup with VLAN name</title>
      <link>https://community.cisco.com/t5/wireless/aaa-vlan-assignment-per-flexgroup-with-vlan-name/m-p/3018428#M143919</link>
      <description>&lt;P&gt;Hello, I have a topology with a virtual WLC (installed on virtual machine) with APs in Flex connect mode. Also I had configured one SSID with authentication to a microsoft radius server (where depending on the account from the active directory the user is assigned to a specific vlan). The problem is when in the radius server return vlan name, then all the clients are add to the default vlan. Then I get an error:&lt;/P&gt;
&lt;P&gt;TLV-DEC-ERR: can not process TLV for TLV_FLEX_VLAN_NAME_ID_MAPPING_PAYLOAD (591/0)&lt;BR /&gt;TLV-DEC-ERR: No CB for TLV_FLEX_VLAN_NAME_ID_MAPPING_PAYLOAD (591)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Is there a fix to this problem?&lt;/P&gt;
&lt;P&gt;When the Radius server return vlan id everiting is working fine, and the clients are add to the specific vlan.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial','sans-serif';"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 13:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aaa-vlan-assignment-per-flexgroup-with-vlan-name/m-p/3018428#M143919</guid>
      <dc:creator>mtsankova</dc:creator>
      <dc:date>2021-07-05T13:50:49Z</dc:date>
    </item>
    <item>
      <title>What you are trying to do is</title>
      <link>https://community.cisco.com/t5/wireless/aaa-vlan-assignment-per-flexgroup-with-vlan-name/m-p/3018429#M143920</link>
      <description>&lt;P&gt;What you are trying to do is called AAA override. Where our AAA server is dictating or overriding our VLAN assignment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sounds like your Radius server is returning the attribute but your AP may not be aware of the VLAN in question.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Guidelines and Limitations&lt;BR /&gt;• VLAN overrides for FlexConnect is applicable for both centrally and locally authenticated clients.&lt;BR /&gt;• &lt;SPAN style="color: #ff0000;"&gt;Before configuring an AAA override, the VLAN must be created on the access points.&lt;/SPAN&gt; These&lt;BR /&gt;VLANs can be created on the access points by using the existing WLAN-VLAN mappings.&lt;BR /&gt;• VLANs can be configured on FlexConnect groups. VLANs are pushed to the access points&lt;BR /&gt;belonging to the FlexConnect group.&lt;BR /&gt;• At any given point, an AP has a maximum of 16 VLANs. The VLANs are selected based on the&lt;BR /&gt;WLAN-VLAN mapping in the AP . The remaining VLANs will be pushed from the Flexconnect&lt;BR /&gt;group in the order that they are configured/shown in the Flexconnect group. If the VLAN slots are&lt;BR /&gt;full, an error message is logged.&lt;BR /&gt;• If the VLAN on the AP is configured using the WLAN-VLAN, the AP configuration of the ACL is&lt;BR /&gt;applied.&lt;BR /&gt;• If the VLAN is configured using the FlexConnect group, the ACL configured on the FlexConnect&lt;BR /&gt;group is applied.&lt;BR /&gt;• If the same VLAN is configured on the FlexConnect group and also at the AP, the AP configuration&lt;BR /&gt;with its ACL takes precedence.&lt;BR /&gt;• If there is no slot for a new VLAN from the WLAN-VLAN mapping, the latest FlexConnect group&lt;BR /&gt;VLAN is replaced.&lt;BR /&gt;• If the VLAN that was returned from the AAA is not present on the AP, the client falls back to the&lt;BR /&gt;default VLAN configured for the WLAN.&lt;BR /&gt;• AAA for locally switched clients only supports VLAN overrides.&lt;BR /&gt;• &lt;SPAN style="color: #ff0000;"&gt;AAA Override for FlexConnect is supported through IETF parameters in the ACS. The following&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;parameters must be configured with the specified values as defined below for a user:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;– [064] Tunnel-Type : Tag 1 value VLAN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;– [065] Tunnel-Medium Type : Tag1 value 802&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;– [081] Tunnel-Private-Group-ID : Tag1 value : Overridden VLAN ID.&lt;/SPAN&gt;&lt;BR /&gt;• Dynamic VLAN assignment is not supported for web authentication from a controller with ACS.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps. Its available in the config guide.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 16:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aaa-vlan-assignment-per-flexgroup-with-vlan-name/m-p/3018429#M143920</guid>
      <dc:creator>William Kuczmera</dc:creator>
      <dc:date>2017-04-11T16:42:41Z</dc:date>
    </item>
    <item>
      <title>Hello, William</title>
      <link>https://community.cisco.com/t5/wireless/aaa-vlan-assignment-per-flexgroup-with-vlan-name/m-p/3018430#M143921</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hello,&amp;nbsp;William&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"Sounds like your Radius server is returning the attribute but your AP may not be aware of the VLAN in question."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The VLAN is configured on the AP via FlexConnect Group. Also FlexConnect VLAN Template is configured.&lt;/P&gt;
&lt;P&gt;The problem only exists, when RADIUS server is configured to return VLAN NAME instead of VLAN ID and when AP is on FlexConnect mode with Central Switching (in this case AAA override works with VLAN NAME), but when the AP lost connection to the WLC (and starts to authenticate locally), then the AP is not aware of the VLAN name to ID mapping, therefore it puts the client on the default VLAN.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;These errors are shown, when AP is joining to the FlexConnect Group initially, configured with FlexConnect VLAN Template. I&amp;nbsp;think this is the main reason, AP not to be aware of VLAN name to ID mapping, therefore it can't override the VLAN when authenticate users&amp;nbsp;by itself (Local Auth).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We use&amp;nbsp;VLAN IDs, instead of VLAN NAMES for '&lt;SPAN&gt;Tunnel-Private-Group-ID' attribute&lt;/SPAN&gt;&amp;nbsp;as workaround for this issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TLV-DEC-ERR: can not process TLV for TLV_FLEX_VLAN_NAME_ID_MAPPING_PAYLOAD (591/0)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;TLV-DEC-ERR: No CB for TLV_FLEX_VLAN_NAME_ID_MAPPING_PAYLOAD (591)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2017 09:26:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aaa-vlan-assignment-per-flexgroup-with-vlan-name/m-p/3018430#M143921</guid>
      <dc:creator>smartitbg</dc:creator>
      <dc:date>2017-06-20T09:26:33Z</dc:date>
    </item>
  </channel>
</rss>

