cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5058
Views
5
Helpful
10
Replies

Dynamic vlan assignment does not work

Hello,

I have been trying to configure dynamic vlan assignment for the employee wlan. Trying to put the employee on vlan 20

Here are the components used

WLC: 2100 Software version: 7.0.240.0

AP: 3502I    IOS version: 12.4  Mini IOS version: 7.0

Radius server: tried mutiple radius servers (rsa radius , free radius)

On the WLC:

-----------------

1. Created a AAA server.

2. Along with management interface(vlan 10), configured dynamic interfaces (vlan 20, vlan 30)

3. AP manager interface is on vlan 40

4. Created WLAN assigned to management interface-- WPA2 (AES) , 802.1x

5. on AAA servers tab - checked authentication servers and assigned the AAA server. authentication priority order is set to only radius

Here, I have 2 options for radius overwrite.

one on the AAA servers tab

second on the Advanced tab

I have selected both. or one at a time

Ports between WLC and switch is a trunk

On the AP:

--------------

1. Local mode

2. Port between AP and switch switchport access  - vlan 40

On radius server:

----------------------

configured WLC's management interface as client

and assigned the following attributes

tunnel-type := vlan

tunnel-medium-type = ieee-802

tunnel-private-group-id = 20

When i try to authenticate with an iphone it is successful. But it puts me on the same interface as management interface (vlan10). When i do the packet capture i do see the access-accept but i dont see the attributes.

when i use a radius test utility against the radius server I do receive all the attributes.

Im a newbie on this. Iam i missing something here? any help will be much appreciated.

1 Accepted Solution

Accepted Solutions

Take a look at this setup:

http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113591-aaa-override-acs52-00.html

What radius server are you using?

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

View solution in original post

10 Replies 10

Scott Fella
Hall of Fame
Hall of Fame

The AAA override needs to be enabled on the WLAN advanced tab, don't use the entry in the AAA server tab.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

Thank you for the reply.

I have selected the  Allow AAA override on the advanced tab. Tried the authentication but fails to put me on the right vlan.

Please note that in the access-accept i donot see the tunnel attributes. However i see them on the access-challenge from the radius.

Take a look at this setup:

http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113591-aaa-override-acs52-00.html

What radius server are you using?

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

Thank you for the replys.

Im using freeradius running on a linux machine.

I was having trouble getting the attributes from RSA radius server. So, i configured a user on users folder of freeradius. When i use  Ntradping and test the connection i see that radius server returns the  tunnel attributes.  (vlan, ieee-802 , vlan-id)

Both the links you guys have provided are very useful but unfortunately we wont have a ACS until next month.

Scott--

I have followed step-by-step frm the link you provided either pc/phone it still puts me on the same vlan as management interface.

Please let me know if i need to upload any packet captures or configuration files.

No problem... if you have the attributes being passed back to the WLC, then the WLC will look at that attribute and assign the correct vlan, as long as AAA override is enabled on the WLAN advanced tab.  I would look at the log on FreeRadius (if there is one) and or sniff the packets to and from the radius to the WCL and verify that it is being sent.

Thanks,

Scott

*****Help out other by using the rating system and marking answered questions as "Answered"*****

-Scott
*** Please rate helpful posts ***

You can try these other attribures for airespace:

http://www.cisco.com/c/en/us/support/docs/wireless/4100-series-wireless-lan-controllers/96103-wlc-attributes.html#c2

Thanks,

Scott

*****Help out other by using the rating system and marking answered questions as "Answered"*****

-Scott
*** Please rate helpful posts ***

Rasika Nayanajith
VIP Alumni
VIP Alumni

Here is a sample configuration with WLC 7.0.116.0 & ACS 5.2.

http://mrncciew.com/2013/05/21/aaa-override-in-acs5-2/

HTH

Rasika

**** Pls rate all useful responses ****

I wanted to give an update on this.

We expedited our order for ACS and i was able to configure and test the setup based on the above documents within 30mins.

I now need to figure out how to do this with NPS.

Thank you all for the help!

Take a look at this link

https://lavazzza.wordpress.com/2010/05/29/wlc-school-for-network-admin?s-who-can-read-real-good-part-2-ok-so-it-has-been-awhile/

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***
Review Cisco Networking for a $25 gift card