VLAN authorization
You can specify authorization VLANs for a WLAN client to control the client's access to network resources. When the client passes 802.1X or MAC authentication, the authentication server assigns the authorization VLAN information to the authenticator. When the device acts as the authenticator, it can resolve server-assigned VLANs of the following formats:
VLAN ID.
VLAN name.
VLAN group name.
VLAN ID and VLAN name combination.
NOTE: The device converts VLAN names and VLAN group names into VLAN IDs before it assigns a VLAN to the client. If the device receives a group of VLANs from the server, it selects the VLAN with the lowest ID for VLAN authorization. | ||
The device fails VLAN authorization for a client in the following situations:
The device fails to resolve the authorization VLAN information.
The server assigns a VLAN name to the device, but the device does not have any VLAN using the name.
The server assigns a VLAN group name to the device, but the VLAN group does not exist or the VLAN group has not been assigned any VLAN.
In AC hierarchical networks, the device for data forwarding and the authenticator can be different devices. For example, the central AC performs authentication and the local AC or AP forwards data traffic.
Authorization VLAN information is used to control data forwarding, so they must be assigned by the device that forwards data traffic. VLAN assignment can be local VLAN assignment or remote VLAN assignment, depending on whether the authenticator and the forwarding device are the same device.
Local VLAN assignment—The authenticator and the forwarding device are the same device. After the authenticator obtains the authorization VLAN information, it resolves the information and assigns the VLAN.
Remote VLAN assignment—The authenticator and the forwarding device are different devices. After the authenticator obtains the authorization VLAN information, it sends the information to the remote forwarding device. The forwarding device then resolves the information and assigns the VLAN.
For more information about VLANs, see Layer 2—LAN Switching Configuration Guide.