User's Manual
14-9
Cisco IOS Software Configuration Guide for Cisco Aironet Access Points
OL-11350-01
Chapter 14 Configuring VLANs
 Configuring VLANs
Using a RADIUS Server for Dynamic Mobility Group Assignment
You can configure a RADIUS server to dynamically assign mobility groups to users or user groups. This 
eliminates the need to configure multiple SSIDs on the access point. Instead, you need to configure only 
one SSID per access point. 
When users associate to the SSID, the access point passes their login information to WLSM, which 
passes the information to the RADIUS server. Based on the login information, the RADIUS server 
assigns the users to the appropriate mobility group and sends their credentials back.
To enable dynamic mobility group assignment, you need to configure the following attributes on the 
RADIUS server:
• Tunnel-Type (64)
• Tunnel-Medium-Type(65)
• Tunnel-Private-Group-ID (81) 
Figure 14-2 Dynamic Mobility Group Assignment
Viewing VLANs Configured on the Access Point
In privileged EXEC mode, use the show vlan command to view the VLANs that the access point 
supports. This is sample output from a show vlan command:
Virtual LAN ID: 1 (IEEE 802.1Q Encapsulation)
 vLAN Trunk Interfaces: Dot11Radio0
FastEthernet0
Virtual-Dot11Radio0
 This is configured as native Vlan for the following interface(s) :
Dot11Radio0
FastEthernet0










