
l Tunnel-Connection-Id
l Tunnel-Medium-Type
l Tunnel-Preference
l Tunnel-Private-Group-Id
l Tunnel-Server-Auth-Id
l Tunnel-Server-Endpoint
l Tunnel-Type
l User-Category
l User-Name
l User-Vlan
l Vendor-Specific
VLAN Derivation Rule
When an external RADIUS server is used for authentication, the RADIUS server may return a reply message for
authentication. If the RADIUS server supports return attributes, and sets an attribute value to the reply message, the
OAW-IAP can analyze the return message and match attributes with a user pre-defined VLAN derivation rule. If the
rule is matched, the VLAN value defined by the rule is assigned to the user.
Figure 54 Configuring RADIUS Attributes on the RADIUS Server
User Role
If the VSA and VLAN derivation rules are not matching, then the user VLAN can be derived by a user role.
AOS-W Instant 6.2.1.0-3.3| User Guide Roles and Policies | 173
Komentarze do niniejszej Instrukcji