WESM zl Management and Configuration Guide WT.01.28 and greater

1-34
Introduction
ProCurve Wireless Edge Services zl Module
The Wireless Edge Services zl Module can read these attributes from an external
RADIUS server:
VLAN assignment
ACL
rate limit, which applies to ingress traffic (traffic from the wireless station to the
network)
Remember that the Wireless Edge Services zl Module can also act as a RADIUS
server. The module supports only dynamic VLAN assignments on its internal
RADIUS server.
Figure 1-12 shows how the user-based settings on the RADIUS server allow the
Wireless Edge Services zl Module to assign users who connect to the same WLAN
to different VLANs.
Figure 1-12. Assigning Wireless Stations to User-Based VLANs
It does not matter how you actually configure these attributes on the RADIUS server.
However, ProCurve IDM greatly simplifies the configuration process. Using Pro-
Curve IDM, you create policies to control individual users’ network access, depend-
ing on the time and location from which they connect. An IDM agent automatically
configures the correct attributes on the RADIUS server. (For more information about
ProCurve IDM, see the ProCurve Identity Driven Manager User’s Guide. You can
download this guide from www.hp.com/go/procurve/manuals.)
If you are using your Wireless Edge Services zl Module’s internal RADIUS server,
you can set this user-based policy: VLAN ID.