FortiAuthenticator - Assing dynamic VLAN to Wifi user

Problem

Depending on the user or user group, a different VLAN ID is to be assigned in the WLAN. 

Solution

FortiAuthenticator

On FortiAuthenticator, the following RADIUS attributes must be assigned either per user or per group:

FortiGate

In order for the FortiGate unit to accept the attributes and assign them to the user, the Dynamic VLAN assignment option must be enabled in the SSID profile.

A static VLAN can be defined via the CLI if the RADIUS server does not send any attributes.
config wireless-controller vap
  edit example-wifi
    set vlanid 10
  next
end
IMPORTANT: Please make sure, that all needed VLAN interfaces are configured on all switches, routers and firewalls - as well on the FortiGate.

Comments

Popular posts from this blog

FortiGate BGP dual-home with multiple ISP

FortiGate as DNS Server or DNS Proxy

FortiGate and Windows L2TP / IPsec with Split Tunneling