Assigning And Clearing Encryption Types On A Radius Server; Keeping Users On The Same Vlan Even After Roaming - D-Link DWS-1008 - AirPremier MobileLAN Switch Product Manual

8 port 10/100 wireless switch with power over ethernet
Hide thumbs Also See for DWS-1008 - AirPremier MobileLAN Switch:
Table of Contents

Advertisement

Assigning and Clearing Encryption Types on a RADIUS Server

To assign or delete an encryption algorithm as the Encryption-Type authorization attribute in a user or
group record on a RADIUS server, see the documentation for your RADIUS server.

Keeping Users on the Same VLAN Even After Roaming

In some cases, a user can be assigned to a different VLAN after roaming to another switch. The table
below lists the ways a VLAN can be assigned to a user after roaming from one DWS-1008 to another.
Location Policy
Yes
No
No
No
No
Yes in the table means the VLAN is set on the roamed-to switch, by the mechanism indicated by the
column header. No means the VLAN is not set. Yes or No means the mechanism does not affect the
outcome, due to another mechanism that is set.
The VLAN Assigned By column indicates the mechanism that is used by the roamed-to switch to assign
the VLAN, based on the various ways the VLAN is set on that switch.
• Location Policy means the VLAN is assigned by a location policy on the roamed-to switch.
(The VLAN is assigned by the vlan vlan-id option of the set location policy permit
command.)
• AAA means the Vlan-name attribute is set on for the user or the user's group, in the
roamed-to switch's local database or on a RADIUS server used by the roamed-to switch to
authenticate the user. (The VLAN is assigned by the vlan-name vlan-id option of the set
user attr, set usergroup attr, set mac-user, or set mac-usergroup command.)
• keep-initial-vlan means that the VLAN is not reassigned. Instead, the VLAN assigned on
the switch where the user first accesses the network is retained. (The keep-initial-vlan
option is enabled by the set service-profile name keep-initial-vlan enable command,
entered on the roamed-to switch. The name is the name of the service profile for the SSID
the user is associated with.)
• SSID means the VLAN is set on the roamed-to switch, in the service profile for the SSID
the user is associated with. (The Vlan-name attribute is set by the set service-profile
name attr vlan-name vlan-id command, entered on the roamed-to switch. The name is the
name of the service profile for the SSID the user is associated with.)
• As shown in the table above, even when keep-initial-vlan is set, a user's VLAN can be
reassigned by AAA or a location policy.
D-Link DWS-1008 User Manual
AAA
keep-initial-vlan
Yes or No
Yes or No
Yes
Yes or No
No
Yes
No
No
No
No
SSID
VLAN Assigned By...
Yes or No
Yes or No
Yes or No
Yes
No
Not set - authentication error
location policy
AAA
keep-initial-vlan
SSID


Advertisement

Table of Contents
loading

Table of Contents