Using Auto VLAN

You can use the Auto VLAN feature to assign available VLAN IDs from a configured range of VLANs to users during their enrollment.

The range of VLANs that you configure creates a VLAN pool in the database. Each customer account can have one VLAN pool. Once the pool has been created, you can increase its size by expanding its range. However, if you shrink the size of the pool, existing users who have a VLAN that is outside the new range will maintain that VLAN until the next time they enroll, at which time they are assigned a new VLAN.

There are three main steps to setting up the Auto VLAN feature:

  • Assigning the ${VLAN_POOL_ASSIGNMENT} variable in the desired area of Cloudpath. For example, you can use this variable for certificates, MAC registrations, and external DPSK( eDPSK). Using this variable allows the RADIUS server to select the VLAN port assigned to an authenticated user. This section will use certificates as an example of how to enact the Auto VLAN feature, but refer to Other Areas of the Cloudpath UI Where You Can Use Auto VLAN for additional information.
  • Enabling the feature for your authentication server in the Configuration > Authentication Servers portion of the UI
  • Defining the VLAN Range and the default VLAN in the Administration > System Services portion of the UI.

Configuration Steps for Setting Up the Auto VLAN Feature In a Certificate:

Follow the steps below to configure the Auto VLAN feature in an onboarding certificate:

Note: The same general steps apply if you want to set up Auto VLAN for another area of the UI where you define a VLAN

  1. Go to Certificate Authority > Manage Templates.
    1. Click the pencil icon to the right of the onboarding certificate template.
    2. Scroll down to the Policy - RADIUS Attributes section.
    3. In the VLAN ID field, enter the variable: ${VLAN_POOL_ASSIGNMENT} thereby allowing the RADIUS server to select the VLAN port that gets assigned to an authenticated user.

      Certificate Template VLAN Variable Setting

    4. Click Save.
    5. To confirm that the variable setting was properly set, you can go to Configuration > RADIUS Server, click the Policies tab. Under the "Success Policy Attributes" column, you should see the variable:

      Confirming VLAN Variable in RADIUS Server Policies

  2. For each traditional authentication server that you want to support this feature, you must enable the "Use VLAN Range" check box:
    1. Go to Configuration > Authentication Servers.
    2. Whether you are adding a new authentication server or need to edit the configuration of an existing authentication server, go to its configuration, as shown in the example figure below for an Active Directory authentication server.
    3. Enable the "Use VLAN Range" checkbox, as shown in the figure below. (Note that it is not enabled by default.)

      Enabling Checkbox to Use VLAN Range on Active Directory Authentication Server

      Note: Without this check box enabled, a VLAN will not be assigned to a user, and any currently assigned VLANs will be removed from users if they re-enroll by means of an authentication server where this box is not checked.
    4. Click Save.
  3. Go to Administration > System Services:

    System Services Page

    1. Scroll down and click the pencil icon to the right of the "Auto VLAN Assignment" service.
    2. Set the values as desired in the VLAN Assignment window; an example is shown below:

      VLAN Assignment Window in System Services

      • VLAN Range: Range to use for automatic VLAN assignment. A single user is assigned the same VLAN for all devices. Any changes to the range will affect future enrollments only.

        Example of how to specify a range in a valid format: 1-142, 532, 1000-1235

      • Default VLAN: The VLAN to use once all other VLANs defined in the pool have been assigned to other users.
    3. Click Save.

      The following figure shows the Auto VLAN Assignment service expanded after the VLAN assignments have been saved:

      Auto VLAN Assignment Information

How the VLAN ID Gets Assigned During Enrollment

As an enrollment is made that uses a traditional authentication server (as specified when you create your workflow), an identity is either created or retrieved from the database. If the identity is on an authentication server with the "Use VLAN Range" checkbox enabled, a VLAN is selected (lowest available number), and the identity is assigned to this VLAN. This VLAN is shown in the User Information section of the Dashboard > Users & Devices page. For example, if the configured the VLAN ranges are 4-5 and 20-24, as shown in the figure above, the first user who enrolls would be assigned a VLAN ID of 4 because 4 would be the lowest available number (see the "VLan Assignment" field in the figure below):

Dashboard: Users & Devices Information Shows VLan Assignment

Note: All devices registered to the same user/identity are assigned the same VLAN ID.

If an authentication server has not been enabled to support the VLAN behavior, then any existing VLAN assignments are removed from the user during enrollment, and that VLAN ID then is released back into the VLAN pool for use by an authentication server that does support the VLAN behavior.

Viewing All VLAN Assignment Information

In the UI, navigate to Dashboards > VLAN Assignments for complete information about VLANs available, assigned, users for each VLAN, and so on.

Other Areas of the Cloudpath UI Where You Can Use Auto VLAN

In addition to using Auto VLAN in certificates, you can also use this feature in the following areas of the Cloudpath UI:

  • External DPSK (eDPSK) - From the UI: Configuration > DPSK Pools > Add DPSK Pool, "VLAN ID" field.
  • MAC Registrations - From the UI: Configuration > MAC Registrations > Add MAC Registration, "Authentication Attributes" section; add the following three Success Reply Attributes:
    • Tunnel-Private-Group-Id (string) - Set this attribute to the variable ${VLAN_POOL_ASSIGNMENT}
    • Tunnel-Type (integer) - Set this value appropriately for your system.
    • Tunnel-Medium-Type (integer) - Set this value appropriately for your system.