
l The user VLANs can be derived from the default roles configured for 802.1X authentication or MAC
authentication.
l After client authentication, the VLAN can be derived from Vendor Specific Attributes (VSA) for RADIUS server
authentication.
l The DHCP-based VLANs can be derived for Captive Portal authentication.
Instant supports role derivation based on DHCP option for Captive Portal authentication. When the
Captive Portal authentication is successful, the role derivation based on DHCP option assigns a new user
role to the guest users, instead of the pre-authenticated role.
Vendor Specific Attributes (VSA)
When an external RADIUS server is used, the user VLAN can be derived from the Alcatel-Lucent-User-Vlan VSA.
The VSA is then carried in an
Access-Accept
packet from the RADIUS server. The OAW-IAP can analyze the return
message and derive the value of the VLAN which it assigns to the user.
Figure 52 RADIUS Access-Accept packets with VSA
Figure 53 Configure VSA on a RADIUS Server
AOS-W Instant 6.2.1.0-3.3| User Guide Roles and Policies | 169
Komentarze do niniejszej Instrukcji