Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
4-88
Wireless Local Area Networks (WLANs)
VLAN Assignment
Identity-Based, or Dynamic, VLAN Assignment
The Wireless Edge Services xl Module can also divide traffic from wireless
users into VLANs based on those users’ identities. This capability (variously
called user-based VLANs or identity-based VLANs, as well as dynamic VLAN
assignment) allows you to:
configure one WLAN for your wireless network with a single SSID and
unified wireless security policy
simultaneously retain granular control over the network rights of each
wireless user
In order for your Wireless Edge Services xl Module to implement dynamic
VLAN assignment in a WLAN, stations must authenticate to a RADIUS server.
This server can be either the modules internal server or an external network
server.
You must also manually enable dynamic VLAN assignment on the WLAN.
You should not use dynamic VLANs in certain circumstances:
You must place the WLAN in a Layer 3 mobility domain—Dynamic VLANs
disable Layer 3 mobility on the WLAN. See Chapter9: Fast Layer2
Roaming and Layer 3 Mobility for guidelines on when a network
requires Layer 3 mobility.
The WLAN requires Web-Auth—Dynamic VLANs can cause complications
because the Web-Auth station receives an IP address before it authenti-
cates. However, if you must, you can enabled dynamic VLAN assignment.
Take care to set the DHCP lease for the static VLAN very low.
On the Wireless Edge Services xl Module, to enable dynamic VLAN assignment
on a WLAN, complete these steps:
1. Access the Edit screen for the WLAN:
a. Select Network Setup > WLAN Setup and click the Configuration tab.
b. Select the WLAN and click the Edit button. The Edit screen is displayed.
2. Verify that the WLAN uses 802.1X EAP, Web-Auth, or MAC authentication.
3. Check the Dynamic Assignment box.
4. Click the OK button.
5. On the RADIUS server, configure users’ VLAN assignments.
a. See “Creating a Group” on page 11-12 in Chapter 11: RADIUS Server
to learn how to configure VLAN assignments on the Wireless Edge
Services xl Module’s internal RADIUS server.