D-Link DWS-1008 User Manual
Assigning and Clearing Encryption Types on a RADIUS Server
To assign or delete an encryption algorithm as the Encryption-Type authorization attribute in a user or
group record on a RADIUS server, see the documentation for your RADIUS server.
Keeping Users on the Same VLAN Even After Roaming
In some cases, a user can be assigned to a different VLAN after roaming to another switch. The table
below lists the ways a VLAN can be assigned to a user after roaming from one DWS-1008 to another.
Location Policy
AAA
keep-initial-vlan
SSID
VLAN Assigned By...
Yes
Yes or No
Yes or No
Yes or No
location policy
No
Yes
Yes or No
Yes or No
AAA
No
No
Yes
Yes or No
keep-initial-vlan
No
No
No
Yes
SSID
No
No
No
No
Not set - authentication error
Yes
in the table means the VLAN is set on the roamed-to switch, by the mechanism indicated by the
column header.
No
means the VLAN is not set.
Yes or No
means the mechanism does not affect the
outcome, due to another mechanism that is set.
The
VLAN Assigned By
column indicates the mechanism that is used by the roamed-to switch to assign
the VLAN, based on the various ways the VLAN is set on that switch.
•
Location Policy
means the VLAN is assigned by a location policy on the roamed-to switch.
(The VLAN is assigned by the
vlan
vlan-id
option of the
set location policy permit
command.)
•
AAA
means the Vlan-name attribute is set on for the user or the user’s group, in the
roamed-to switch’s local database or on a RADIUS server used by the roamed-to switch to
authenticate the user. (The VLAN is assigned by the
vlan-name
vlan-id
option of the
set
user attr, set usergroup attr, set mac-user, or set mac-usergroup command.)
•
keep-initial-vlan
means that the VLAN is not reassigned. Instead, the VLAN assigned on
the switch where the user first accesses the network is retained. (The
keep-initial-vlan
option is enabled by the
set service-profile
name
keep-initial-vlan enable command,
entered on the roamed-to switch. The name is the name of the service profile for the SSID
the user is associated with.)
•
SSID
means the VLAN is set on the roamed-to switch, in the service profile for the SSID
the user is associated with. (The Vlan-name attribute is set by the
set service-profile
name
attr vlan-name
vlan-id
command, entered on the roamed-to switch. The
name
is the
name of the service profile for the SSID the user is associated with.)
• As shown in the table above, even when
keep-initial-vlan is set, a user’s VLAN can be
reassigned by AAA or a location policy.
Содержание DWS-1008
Страница 1: ......