Users Guide

Table Of Contents
You cannot modify a VLAN name, so choose the name carefully.
Named VLANs (single VLAN IDs or multiple VLAN IDs) can only be assigned to tunnel mode VAP’s and wired
profiles. They can also be assigned to user roles, user rule derivation, server derivation, and VSA for tunnel and
bridge mode.
For tunnel mode, named VLANs that have the assignment type hash” and even” are supported.
For bridge mode only, named VLANs with the assignment type hash” are supported. If a named VLAN with
even assignment is assigned to a user rule, user role, server derivation or VSA, than the hash” assignment is
applied and the following error message displays:
"named VLAN assignment type EVEN not supported for bridge. Applying HASH algorithm to retrieve vlan-id"
L2 roaming is not supported with an even VLAN assignment.
In the CLI
To apply a named VLAN in a user rule, use the following CLI commands:
(host)(config) #aaa derivation-rules
(host)(config) #aaa derivation-rules user <string>
(host)(config) #aaa derivation-rules user test-user-rule
(host)(user-rule) #set vlan
To apply a named VLAN in a user role, use the following CLI commands:
(host)(config) #user-role test-vlan-name
(user)(config-role) #vlan test-vlan
To apply a named VLAN in server derivation, use the following CLI commands:
(host)(config) #aaa server-group test-vlan-server-group
(user)(Server Group "test-vlan-server-group") set vlan
For a named VLAN derivation using VSA, configure the RADIUS server using these values:
Aruba-Named-UserVLAN 9 String Aruba 14823
In the WebUI
To apply a named VLAN in a user rule, navigate to the WebUI page:
Security > Authentication > User Rules
To apply a named VLAN in a user role, navigate to the WebUI page:
Security > Access Control > User Roles > Add or Edit Role
To apply a named VLAN in a server derivation (server group), navigate to the WebUI page:
Security > Authentication> Servers > Server Group > <server-group_name> >Server Rules
Adding a Bandwidth Contract to the VLAN
Bandwidth contracts on a VLAN can limit broadcast and multicast traffic. ArubaOS includes an internal
exception list to allow broadcast and multicast traffic using the VRRP, LACP, OSPF, PVST, and STP protocols. To
remove per-VLAN bandwidth contract limits on an additional broadcast or multicast protocol, add the MAC
address for that broadcast/multicast protocol to the VLAN Bandwidth Contracts MAC Exception List.
The command in the example below adds the MAC address for CDP (Cisco Discovery Protocol) and VTP (Virtual
Trunking Protocol to the list of protocols that are not limited by VLAN bandwidth contracts.
(host)(config) #vlan-bwcontract-explist mac 01:00:0C:CC:CC:CC
Dell Networking W-Series ArubaOS 6.5.x | User Guide Network Configuration Parameters |
104