195 | Roles and Policies Dell Networking W-Series Instant 6.4.0.2-4.1 | User Guide
l The user VLANs can be derived from the default roles configured for 802.1X authentication or MAC
authentication.
l After client authentication, the VLAN can be derived from Vendor Specific Attributes (VSA) for RADIUS server
authentication.
l The DHCP-based VLANs can be derived for Captive Portal authentication.
Instant supports role derivation based on the DHCP option for Captive Portal authentication. When the Captive
Portal authentication is successful, the role derivation based on the DHCP option assigns a new user role to the
guest users, instead of the pre-authenticated role.
Vendor Specific Attributes
When an external RADIUS server is used, the user VLAN can be derived from the Dell-User-Vlan VSA. The VSA is
then carried in an
Access-Accept
packet from the RADIUS server. The W-IAP can analyze the return message and
derive the value of the VLAN which it assigns to the user.
Figure 57 RADIUS Access-Accept packets with VSA
Figure 58 Configure VSA on a RADIUS Server
Comments to this Manuals