Figure 46 Configure VSA on a RADIUS Server
VLAN Assignment Based on Derivation Rules
When an external RADIUS server is used for authentication, the RADIUS server may return a reply message for
authentication. If the RADIUS server supports return attributes, and sets an attribute value to the reply
message, the IAP can analyze the return message and match attributes with a user pre-defined VLAN derivation
rule. If the rule is matched, the VLAN value defined by the rule is assigned to the user. For a complete list of
RADIUS server attributes, see
RADIUS Server Authentication with VSA on page
151.
Figure 47 Configuring RADIUS Attributes on the RADIUS Server
205
| Roles and Policies
Aruba Instant 6.5.0.0-4.3.0.0 | User Guide