Hi All,
We have L2 network infrastructure based on two Cisco Small (one SGE2000P and one SGE2010, both in stacking). We have multiple VLAN for various organization unit and we need authentication of users connected to wired port (users need to move in the office and use all wired network connection available) end dynamic vlan assigment based on authentication. Authentication works well with freeradius and eap-tls with certs on Radius and Clients (Windows and Linux), but Switch don't apply VLAN directive from radius. The radius reply to Cisco Switch with
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "31"
or
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "Admins"
but users access to PVID VLAN on every successful authentication (ignoring vlan directive from radius)
Are these switch capable of dynamic vlan assignment based on 802.1x? Anybody have some tips?
Thanks