Specifications
Configuring and Managing VLANs
RoamAbout Mobility System Software Configuration Guide 4-15
Users and VLANs
Whenausersuccessfullyauthenticatestothenetwork,theuserisassignedtoaspecificVLAN.A
userremainsassociatedwiththesameVLANthroughouttheuser’ssessiononthenetwork, even
whenroamingfromoneRoamAboutSwitchtoanotherwithintheMobilityDomain.
YouassignausertoaVLAN
bysettingoneofthefol lowing attributesontheRADIUSserversor
inthelocaluserdatabase:
•Tunnel‐Private‐Group‐ID—ThisattributeisdescribedinRFC2868,RADIUSAttributesfor
TunnelProtocolSupport.
•VLAN‐Name—ThisattributeisanEnterasysvendor‐specificattribute(VSA).
SpecifytheVLANname,nottheVLANnumber.
TheexamplesinthischapterassumetheVLAN
isassignedonaRADIUSserverwitheitherofthevalidattributes.(Formoreinformation,see
Chapter 17,”ConfiguringAAAforNetworkUsers”.)
VLAN Names
TocreateaVLAN,youmustassignanametoit.VLANnamesmustbegloballyuniqueacrossa
MobilityDomaintoensuretheintendeduserconnectivityasdeterminedthroughauthentication
andauthorization.
EveryVLANonaRoamAbou tSwitchhasbothaVLANname,usedforauthorizationpurposes,
andaVLAN
number.VLANnumberscanvaryuniquelyforeachRoamAboutSwitchandarenot
relatedto802.1Qtagvalues.
YoucannotuseanumberasthefirstcharacterinaVLANname.
Roaming and VLANs
RoamAboutswitchesinaMobilityDomaincontainauser’strafficwithintheVLANthattheuser
isassignedto.Forexample,ifyouassignausertoVLANred,theRoamAboutswitchesinthe
MobilityDomaincontaintheuser’strafficwithinVLANredconfiguredontheswitches.
TheRoamAboutSwitchthrough
whichauserisauthenticatedisnotrequiredtobeamemberof
theVLANtheuserisassignedto.YouarenotrequiredtoconfiguretheVLANonallRoamAbout
switchesintheMobilityDomain.Whenauserroamstoaswitchthatisnotamemberofthe
VLANtheuserisassignedto,theswitchcantunneltrafficfortheuserthroughanotherswitch
thatisamemberoftheVLAN.Thetrafficcanbeofanyprotocoltype.
(Formoreinformation
aboutMobilityDomains,seeChapter 7,”ConfiguringandManagingMobilityDomain
Roaming”.)
Note: You cannot configure the Tunnel-Private-Group-ID attribute in the local user database.
Note: Because the default VLAN (VLAN 1) might not be in the same subnet on each switch,
Enterasys Networks recommends that you do not rename the default VLAN or use it for user traffic.
Instead, configure other VLANs for user traffic.