le 04-05-2023 06:26 AM
Hello,
I currently use a cisco switch CBS250-48T-4G on the firmware 3.3.0.16 and i would like to know if this is possible to assign VLAN dynamically with my RADIUS server.
I managed to setup this configuration with a netgear cisco, but i can't find the settings that take the VLAN ID from the packet sent from RADIUS server to the cisco switch, and change de PVID of the port used. (the 802.1x authentication work fine)
Is dynamic VLAN assignement is a feature that support the CBS250?
Thank in advance
KM
le 04-05-2023 06:33 AM
Hello @KMatgp,
To configure dynamic VLAN assignment on the CBS250 switch, you need to configure the RADIUS server to send the VLAN ID in the RADIUS attribute 64 (Tunnel-Private-Group-ID) or 65 (Tunnel-Type and Tunnel-Medium-Type). Once the RADIUS server sends the VLAN ID to the switch, the switch can assign the VLAN dynamically to the port based on the user's authentication credentials.
le 04-05-2023 06:59 AM
le 04-05-2023 07:08 AM
Yes @KMatgp, there are several RADIUS attributes that can be used to dynamically assign VLANs on a Cisco switch based on the authentication result received from the RADIUS server. The most common attribute used for this purpose is the "Tunnel-Private-Group-Id" (Tunnel-PGID) attribute. This attribute is used to specify the VLAN ID that the authenticated user should be placed into.
le 09-05-2023 01:12 AM
le 09-05-2023 01:28 AM
Hello @KMatgp,
In order to assign a VLAN dynamically using RADIUS, the port should be in "General Mode Membership" or "Trunk Mode Membership". However, it is important to note that the VLAN ID sent from the RADIUS server needs to match an existing VLAN on the switch for the assignment to work.
le 17-04-2024 02:57 AM
Hello M02@rt37,
we have the same problem with CBS250-16P. I am not sure about the RADIUS attributes.
Our settings are: attribute 64 (Tunnel-Type) = Virtual LANs (VLAN)
attribute 65 (Tunnel-Medium-Type) = 802 (includes all 802 plus Ethernet...)
attribute 81 (Tunnel-Pvt-Group-ID) = 108
It's working with all other Cisco-Switches.
On CBS250: GVRP is set globally and on the port;
port is in "General Mode Membership";
VLAN 108 still exists;
Port still stay in VLAN 1
Any suggests?
Guido
Découvrez et enregistrez vos notes préférées. Revenez pour trouver les réponses d'experts, des guides étape par étape, des sujets récents et bien plus encore.
Êtes-vous nouveau ici? Commencez par ces conseils. Comment utiliser la communauté Guide pour les nouveaux membres
Parcourez les liens directs de la Communauté et profitez de contenus personnalisés en français