Roles and Policies
15.4 Configuring Derivation Rules
SCALANCE W1750D UI
Configuration Manual, 02/2018, C79000-G8976-C451-02
275
Configuring VLAN Derivation Rules
The VLAN derivation rules allow administrators to assign a VLAN to the AP clients based on
the attributes returned by the RADIUS server.
You can configure VLAN derivation rules for an SSID profile by using the SCALANCE W UI
or the CLI.
To configure VLAN derivation rules:
1. Perform the following steps:
–
To configure VLAN derivation rule for a WLAN SSID profile, navigate to
Network >
New > New WLAN > VLAN
or
Network > edit > Edit <WLAN-profile> > VLAN
. Select
the
option under the Client VLAN assignment
– To configure VLAN derivation rule for a wired network profile, navigate to
or . The tab contents are displayed.
2. Click
to create a VLAN assignment rule. The
window is
displayed. In this window, you can define a match method by which the string in
Operand
is matched with the attribute values returned by the authentication server.
Figure 15-7 VLAN Assignment Rule Window
3. Select the attribute from the
drop-down list. The list of supported attributes
includes RADIUS attributes, dhcp-option, dot1x-authentication-type, mac-address, and
mac-address-and-dhcp-options. For information on a list of RADIUS attributes, see
RADIUS Server Authentication with VSA. (Page 209)