dynamic assignment of VLANs from LDAP via freeradius to WLAN-Clients doesn't work properly

Meister, Frank Frank.Meister at hmt-hannover.de
Thu May 27 18:42:29 CEST 2010


Hello,

we have freeradius-2.1.8 running, with openldap-2.3.43 as backend. 
in ldap we have three attributes (radiusTunnelMediumType=IEEE-802, 
radiusTunnelType=VLAN, and radiusTunnelPrivateGroupId=[vlan-id]), 
freeradius maps the ldap-attributes to radius-attributes.

We have three vlans, one for staff, one for students and one for guests
on the WLAN.

after assigning the 1st VLAN on our cisco aironet 1242 accesspoints
to the SSID -> clicking Apply, assigning the 2nd VLAN -> click Apply,
assigning the 3rd VLAN, click Apply it works fine.
(I mean manual assigning VLANs using web-interface)

after reboot of the accesspoint it doesn't work anymore. after assign
all three VLANs again, one after the other, it works.

has anybody an idea about what I'm doing wrong ? 
the command "aaa authorization network default group radius" from the
Cisco-site I tried, but it didn't help further.
  

Thanks for some help,
Frank Meister




More information about the Freeradius-Users mailing list