Does anyone running a Cisco 1220 AP that has been upgraded to IOS have per user VLAN's working?
I have many Vxworks AP's that this is working on, but I upgraded one of my spares to the latest IOS and my laptop never gets moved to the correct VLAN.
There is a BudID CSCin46150 that says:
When a RADIUS Server is configured for a different VLAN (say 10)to be assigned to the user (client), than the one established with the SSID (say 5) , the client gets assigned the original VLAN (as defined for the SSID, here 5) rather that the one sent
by the ACS (VLAN 10).
It states it is fixed in 12.2(11)JA01, but I am still having the same problem. I see the information (private-group-id) being sent from the radius server (2000 server IAS) with a sniffer, but my laptop never is switched to that VLAN.
Does anyone have this working with IAS, or does anyone have this working with ACS?
Hi Don. What I had to do to get this working was on IAS was to put the Tunnel Tag attribute in my Remote Access Policy. I just set it to 10. Worked like a champ (I believe it has to be between 1 and 31).
It is a pretty basic setup with no filters or anything. On My IAS server:
I have NAS-Port-Type matches "Virtual (VPN) - this is because the 1220 IOS version sends this as the port type instead of "Wireless - IEEE 802.11" like the Vxworks AP's...
In the advanced tab -
Tunnel-Medium-Type = 802
Tunnel-Type = Virtual Lans
Tunnel-Pvt-Group-ID = 10031 (note I am trying to assign Vlan ID 31. The first number is added to the Tag 0x3X so if I used 31 as the value the tag would read 0x33 and the Value being sent is 1 so that would assign VLAN 1...This is not mentioned anywhere in Cisco's or Microsofts Docs....If you use a sniffer you can see the information being passed...On my Vxworks I have 10031 and the users are assigned to VLAN 31.)
I played around with the value for Tunnel-Pvt-Group-ID trying everything from 131,1031,0031,031,etc and not matter what, the laptop never gets moved to VLAN 31. I cannot get a DHCP address and if I statically configure an address on the laptop, no traffic passes through the AP. I am watching everthing with a sniffer monitoring all traffic passing through the AP....
I am at a loss. I still cannot get this working on the 1220 IOS AP I have...
BTW - Vxworks users searching for information.... the IAS config above will assign the authenticated user to VLAN 31. Make sure that for the NAS-Port-Type "Wireless - IEEE 802.11"