Home > wireless > Wireless (Ruckus) and Dynamic VLAN Assignment via Microsoft NPS

Wireless (Ruckus) and Dynamic VLAN Assignment via Microsoft NPS

October 11Hits:40
Advertisement

Our current 802.11 setup has a large number of SSIDs to segregate traffic by subnet. This isn't ideal, and I've been attempting to consolidate to a single SSID but use dynamic VLANs instead.

This is on a Ruckus Zonedirector 3000 and Microsoft NPS as the RADIUS server.

My test clients connect to the SSID, and are prompted for credentials. I can see the credentials accepted on the NPS server, and wireshark confirms the Access-Accept message contains the Tunnel-Private-Group-ID value for the desired VLAN.

At this point the client stalls trying to get a DHCP lease. The DHCP server is working, as these are existing scopes and subnets and I can connect a wired client into the switch on an access port for the same vlan and get a lease.

Wireshark shows no DHCP broadcast request from the client at all.

The switchport for the AP is a trunk, with the VLAN tagged and allowed.

Any assistance would be greatly appreciated! Rob

Answers

I found the answer here:

http://forums-archive.ruckuswireless.com/forums/8/topics/1278

NPS does not return AD group memberships back to the ZoneDirector without setting a vendor-specific attribute on NPS. A role has to be configured for each group on the ZoneDirector and a network policy has to be configured for each group on NPS.

This seems rather redundant as I've already got authorization and vlan assignment happening on NPS, why would the ZoneDirector also require a role to authorize access to the specified WLAN? Oh well at least it works now.

Related Articles

  • Wireless (Ruckus) and Dynamic VLAN Assignment via Microsoft NPSOctober 11

    Our current 802.11 setup has a large number of SSIDs to segregate traffic by subnet. This isn't ideal, and I've been attempting to consolidate to a single SSID but use dynamic VLANs instead. This is on a Ruckus Zonedirector 3000 and Microsoft NPS as

  • Need help getting Dynamic VLAN Assignment working with RADIUS and Dell PowerConnect 3524September 5

    I'm attempting to get Dynamic VLAN Assignment working on a number of Dell PowerConnect 3524 switches. I've got a two RADIUS servers, both of which I've proved to be working using radtest on Linux. One of the servers (Priority 0) is hosted on the netw

  • How do I setup dynamic VLAN assignment on an autonomous Cisco 1142n?September 26

    I've gotten my Cisco 1142n autonomous AP configured with every option under the sun, but I still can't get dynamic VLAN assignment working! I verified the following: I give priority to VLAN assignment via RADIUS with aaa authorization network default

  • Regarding Dot1X dynamic VLAN assignmentAugust 28

    Situation: I am trying to get 802.1X working for me. I want RADIUS server to dynamically assign VLANs to ports based on RADIUS reply attribute for particular user. I have an HP E2620 switch and a FreeRADIUS server. The supplicant is a Windows 8.1 mac

  • 802.1x dynamic vlan assignment not assigning VLANMay 12

    I recently dived into 802.1x authentication with dynamic vlan assigment. My current set up contains of: - A client - A SG220 cisco switch (the supplicant) - A freeradius (authenticator) based on an LDAP AD - A fortigate for firewall purposes and acti

  • Freeradius on Linux with dynamic VLAN assignment via ADFebruary 7

    I've been trying to configure my freeradius server on Linux to authenticate users from an existing Active Directory (windows server 2003) and i've already done that. Now i need to assign VLANs to those users and i dont know how to :(. The logical pro

  • Radius NAC with 802.1x on Cisco WLC doesn't assign correct dynamic VLAN ID October 30

    I'm implementing a NAC solution in my company, but I have come to dead end. My setup: Cisco WLC + MS based Radius server integrated with AD. The idea is to have 4 VLANs. Everything works as it should with the wired network but not using the Cisco WLC

  • Registation or Guest VLAN for 802.1x via Microsoft NPSDecember 16

    I am currently working on a Microsoft NPS solution to provide 802.1x MAC authentication for wired and wireless clients along with providing a VLAN for the clients to be moved to. It currently works perfect with our Wireless APs and switches, however

  • Subnet-based VLAN assignment on CiscoAugust 21

    Is it possible to assign a switch port to a VLAN based on the fact that the host IP address is on a certain subnet? I have found the following references from HP and Netgear, but I have been unable to find any such functionality for Cisco. Please not

  • How to Change a VLAN Assignement for an Interface on a Cisco 3750November 10

    I'm having some trouble trying to figure out how to Change a VLAN Assignement for an Interface on a Cisco 3750. I want to change: ! interface GigabitEthernet1/0/3 switchport access vlan 2 switchport mode access spanning-tree portfast ! Into: ! interf

  • Radius VLAN assignmentAugust 24

    Hello to all, I have just start working with Ciitix-wifi. Can someone tell me if with CIITIX-WIFI is possible to do RADIUS-based VLAN assignment, when users authenticate? It appears not but... With some patch... I do no know... Thanks in advanced Bes

  • How to install and configure Dynamic VLAN Server?March 13

    I have below setup: Firewall: Fortinet 240D Core Switches are 2 one is Juniper EX 4200 & second one is EX 3300 I want to configure Dynamic VLAN Server on Ubuntu Linux 12.04.3 Kernel and CPU: Linux 3.8.0-32-generic on i686 I have confirmed with Junnip

  • Microsoft NPS Radius Proxy - Framed-IP-Address EmptyMarch 18

    I'm trying to use Microsoft's NPS as a radius proxy, but for some reason it's not forwarding the Framed-IP-Attribute in the accounting requests. I have a Meru wireless controller, Smoothwall web filter, Cloudpath XpressConnect wireless onboarding (ho

  • Use mail attribute for 802.1x RADIUS authenticatioon with Microsoft NPSDecember 17

    We have run a Cisco WiFi network that uses 802.1x to authentication logins against Active Directory. Employees login using their UPN prefix, and all works well. For various reasons we'd like users to be able to log in with their email address (stored

  • Dynamic VLANs with FreeRadius, OpenLDAP & Cisco WLCAugust 13

    Currently have a FreeRADIUS 1.1.6 server authenticating users from OpenLDAP which are stored in the posixAccount account schema. We've now installed a Cisco WLC, and want to authenticate those users over 802.1X (which is successfully working), but al

  • Cisco ASA 5505: switchport VLAN assignmentNovember 2

    Kind of a Cisco Luddite, but I'd like to assign physical switchports 0/1 and 0/2 to Vlan2 and physical switchports 0/3 and 0/4 to Vlan3. I'm assuming this is possible with base security license, i.e.: ! interface Vlan1 nameif outside security-level 0

  • VLAN assignment based on mac-address or RADIUS attributeOctober 30

    I'd like to know how to assign someone's client device to a different VLAN based on MAC address of that device.What kind of hardware/software would make this solution possible (if possible at all)? Would it be possbible to achieve the same using RADI

  • VLAN assignment philosophy

    VLAN assignment philosophySeptember 3

    I have several Layer 3 switch/routers which are all connected via an OSPF routed network. Also attached to each switch are two other networks. I have to assign a VLAN to each of these networks, I figure that I can just reuse the same two VLANS on eac

  • MikroTik and HP devices - Dynamic VLAN

    MikroTik and HP devices - Dynamic VLANApril 6

    QUESTIONS: Is is possible to do this using MikroTIk CloudCore1036 with all my assumptions ? Do I need Radius to done this ? At above picture You can see part of my network scheme. Main router based on Mikrotik CloudCore1036 within one bridge and HP s

  • Dynamic IP assignment in theory July 25

    This question already has an answer here: If router is off for a few days, do you have an ip address as far as ISP is concerned? 1 answer If I turn my router off for 24 hours or more I am always assigned a new dynamic IP address once I turn it on aga

Copyright (C) 2017 ceus-now.com, All Rights Reserved. webmaster#ceus-now.com 14 q. 0.784 s.