Specifications
Assigning Authorization Attributes
RoamAbout Mobility System Software Configuration Guide 17-51
Yes inthetablemeanstheVLANissetontheroamed‐toRoamAboutSwitch,bythemechanism
indicatedbythecolumnheader.NomeanstheVLANisnotset.YesorNomeansthemechanism
doesnotaffecttheoutcome,duetoanothermechanismthatisset.
TheVLANAssigned
Bycolumnindicatesthemechanismthatisusedbytheroamed‐tosw itchto
assigntheVLAN,basedonthevariouswaystheVLANissetonthatswitch.
• LocationPolicymeanstheVLANisassignedbyalocationpolicyontheroamed‐toswitch.(The
VLANisassignedbythe
vlanvlan‐idoptionofthesetlocationpolicypermitcommand.)
• AAAmeanstheVlan‐nameattributeissetonfortheuserortheuser’sgroup,intheroamed‐to
switch’slocaldatabaseoronaRADIUSserverusedbytheroamed‐toswitchtoauthenticate
theuser.(The
VLANisassignedbythevlan‐namevlan‐idoptionofthesetuserattr,set
usergroupattr,setmac‐user,orsetmac‐usergroupcommand.)
• keep‐initial‐vlanmeansthattheVLANisnotreassigned.Instead,theVLANassignedonthe
switchwheretheuserfirstaccessesthe
networkisretained.(Thekeep‐initial‐vlanoptionis
enabledbythesetservice‐profilenamekeep‐initial‐vlanenablecommand,enteredonthe
roamed‐toswitch.ThenameisthenameoftheserviceprofilefortheSSIDtheuseris
associatedwith.)
• SSIDmeanstheVLANisseton
theroamed‐toswitch,intheserviceprofilefortheSSIDthe
userisassociatedwith.(TheVlan‐nameattributeissetbythesetservice‐profilenameattr
vlan‐namevlan‐idcommand,enteredontheroamed‐toswitch.Thenameisthenameofthe
serviceprofilefor
theSSIDtheuserisassociatedwith.)
•AsshowninTable 17‐6,evenwhenkeep‐initial‐vlanisset,auser’sVLANcanbereassigned
byAAAoralocationpolicy.
Toenablekeep‐initial‐vlan,usethefollowingcommand:
set service-profile name keep-initial-vlan {enable | disable}
Enterthiscommandontheswitchthatwillberoamedtobyusers.
Thefollowingcommandenablesthekeep‐initial‐vlanoptiononserviceprofilesp3:
RBT-8100# set service-profile sp3 keep-initial-vlan enable
success: change accepted.
Note: The keep-initial-vlan option does not apply to Web-Portal clients. Instead, VLAN
assignment for roaming Web-Portal clients automatically works the same way as when
keep-initial-vlan is enabled. The VLAN initially assigned to a Web-Portal user is not
changed except by a location policy, AAA, or SSID default setting on the roamed-to switch.