Using Auto VLAN
The range of VLANs that you configure creates a VLAN pool in the database. Each customer account can have one VLAN pool. Once the pool has been created, you can increase its size by expanding its range. However, if you shrink the size of the pool, existing users who have a VLAN that is outside the new range will maintain that VLAN until the next time they enroll, at which time they are assigned a new VLAN.
There are three main steps to setting up the Auto VLAN feature:
- Assigning the ${VLAN_POOL_ASSIGNMENT} variable in the desired area of Cloudpath. For example, you can use this variable for certificates, MAC registrations, and external DPSK( eDPSK). Using this variable allows the RADIUS server to select the VLAN port assigned to an authenticated user. This section will use certificates as an example of how to enact the Auto VLAN feature, but refer to Other Areas of the Cloudpath UI Where You Can Use Auto VLAN for additional information.
- Enabling the feature for your authentication server in the Configuration > Authentication Servers portion of the UI
- Defining the VLAN Range and the default VLAN in the Administration > System Services portion of the UI.
Configuration Steps for Setting Up the Auto VLAN Feature In a Certificate:
Follow the steps below to configure the Auto VLAN feature in an onboarding certificate:
- Go to
Certificate Authority > Manage Templates.
- Click the pencil icon to the right of the onboarding certificate template.
- Scroll down to the Policy - RADIUS Attributes section.
- In the VLAN ID field, enter the variable: ${VLAN_POOL_ASSIGNMENT} thereby allowing the RADIUS server to select the VLAN port that gets assigned to an authenticated user.
- Click Save.
- To confirm that the variable setting was properly set, you can go to Configuration > RADIUS Server, click the Policies tab. Under the "Success Policy Attributes" column, you should see the variable:
- For each traditional authentication server that you want to support this feature,
you must enable the "Use VLAN Range" check box:
- Go to Configuration > Authentication Servers.
- Whether you are adding a new authentication server or need to edit the configuration of an existing authentication server, go to its configuration, as shown in the example figure below for an Active Directory authentication server.
- Enable the "Use VLAN Range" checkbox, as shown in the figure below. (Note that it
is not enabled by default.)
Note: Without this check box enabled, a VLAN will not be assigned to a user, and any currently assigned VLANs will be removed from users if they re-enroll by means of an authentication server where this box is not checked.
- Click Save.
- Go to
Administration > System Services:
- Scroll down and click the pencil icon to the right of the "Auto VLAN Assignment" service.
- Set the values as desired in the VLAN Assignment window; an example is shown below:
- VLAN Range: Range to use for automatic VLAN assignment. A single user is assigned
the same VLAN for all devices. Any changes to the range will affect future enrollments
only.
Example of how to specify a range in a valid format: 1-142, 532, 1000-1235
- Default VLAN: The VLAN to use once all other VLANs defined in the pool have been assigned to other users.
- VLAN Range: Range to use for automatic VLAN assignment. A single user is assigned
the same VLAN for all devices. Any changes to the range will affect future enrollments
only.
- Click
Save.
The following figure shows the Auto VLAN Assignment service expanded after the VLAN assignments have been saved:
How the VLAN ID Gets Assigned During Enrollment
As an enrollment is made that uses a traditional authentication server (as specified when you create your workflow), an identity is either created or retrieved from the database. If the identity is on an authentication server with the "Use VLAN Range" checkbox enabled, a VLAN is selected (lowest available number), and the identity is assigned to this VLAN. This VLAN is shown in the User Information section of the Dashboard > Users & Devices page. For example, if the configured the VLAN ranges are 4-5 and 20-24, as shown in the figure above, the first user who enrolls would be assigned a VLAN ID of 4 because 4 would be the lowest available number (see the "VLan Assignment" field in the figure below):
If an authentication server has not been enabled to support the VLAN behavior, then any existing VLAN assignments are removed from the user during enrollment, and that VLAN ID then is released back into the VLAN pool for use by an authentication server that does support the VLAN behavior.
Viewing All VLAN Assignment Information
In the UI, navigate to Dashboards > VLAN Assignments for complete information about VLANs available, assigned, users for each VLAN, and so on.
Other Areas of the Cloudpath UI Where You Can Use Auto VLAN
In addition to using Auto VLAN in certificates, you can also use this feature in the following areas of the Cloudpath UI:






