Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
4-82
Wireless Local Area Networks (WLANs)
VLAN Assignment
users. On the other hand, you might tag the port for the wired VLANs
(depending on whether the module has VLAN interfaces for those VLANs or
simply knows routes to them).
The Wireless Edge Services xl Module determines the VLAN to which to assign
incoming wireless traffic based on one of two criteria:
the wireless user’s identity
the wireless station’s WLAN
You configure WLAN-based VLAN assignments manually. (See “Setting Basic
Configuration Options: SSID and Interface” on page 4-30.)
Identity or user-based VLAN assignments are dynamic and received from an
authentication server. This server can be either the Wireless Edge Services xl
Module’s internal RADIUS server on an external RADIUS server. You must
activate dynamic VLANs on a WLAN in order for the module to enforce
dynamic VLAN assignments. (See “Setting Basic Configuration Options: SSID
and Interface” on page 4-30.)
Note that the Wireless Edge Services xl Module can use both kinds of assign-
ment on the same WLAN, but dynamic settings always take precedence when
dynamic VLANs are enabled. For example, you manually assign WLAN 1 to
VLAN 10. Users A, B, and C connect to WLAN 1; however, the RADIUS data-
base only includes a VLAN assignment for users A and B. When user C con-
nects to the WLAN, the module forwards its traffic in VLAN 10. When user A
connects to the WLAN, the authentication server sends users’ VLAN assign-
ment, and the module forwards user As traffic in VLAN 20. (See Figure 4-48.)
Figure 4-48. WLAN Versus Identity-Based VLAN Assignment