Managing a Wireless Local Area Network
Deploying ZoneDirector WLANs in a VLAN Environment
Figure 88.
Priority of VLAN, Dynamic VLAN and Tunnel Mode
If the VLAN, Dynamic VLAN and Tunnel Mode features are all enabled and they have conflicting
rules, ZoneDirector prioritizes and applies these three features in the following order:
1. Dynamic VLAN (top priority)
2. VLAN
3. Tunnel Mode
How It Works
1. User associates with a WLAN on which Dynamic VLAN has been enabled.
2. The AP requires the user to authenticate with the RADIUS server via ZoneDirector.
3. When the user completes the authentication process, ZoneDirector sends the join approval
for the user to the AP, along with the VLAN ID that has been assigned to the user on the
RADIUS server.
4. User joins the AP and is segmented to the VLAN ID that has been assigned to him.
Required RADIUS Attributes
For dynamic VLAN to work, you must configure the following RADIUS attributes for each user:
•
Tunnel-Type: Set this attribute to VLAN.
•
Tunnel-Medium-Type: Set this attribute to IEEE-802.
Enabling Dynamic VLAN
136