<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VLAN Pool AAA override in Cloudpath Enrollment System (ES)</title>
    <link>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/VLAN-Pool-AAA-override/m-p/25392#M132</link>
    <description>I have two certificate templates configured in CloudPath that have a filter ID assigned to them.&amp;nbsp; One of them does what I want and one doesn't (one that works correctly was setup a while back, broken one I am working on now).&amp;nbsp; What happens with the working one is my 802.1x SSID is configured for Dynamic VLAN (AAA Override) . On the controller I have a two user roles created that assign a VLAN pool to that role.&amp;nbsp; Also on the controller under Proxy Authentication where the settings for cloud path are I have the two attributes map to the user role.&amp;nbsp; The one I setup previously correctly assigns the VLAN pool and traffic policy.&amp;nbsp; The new one does not, the client ends up getting a DHCP address from the native vlan.&amp;nbsp; I have a feeling there is something I missed on the controller side but I can't find it.</description>
    <pubDate>Wed, 20 Feb 2019 00:25:31 GMT</pubDate>
    <dc:creator>john_westlund</dc:creator>
    <dc:date>2019-02-20T00:25:31Z</dc:date>
    <item>
      <title>VLAN Pool AAA override</title>
      <link>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/VLAN-Pool-AAA-override/m-p/25392#M132</link>
      <description>I have two certificate templates configured in CloudPath that have a filter ID assigned to them.&amp;nbsp; One of them does what I want and one doesn't (one that works correctly was setup a while back, broken one I am working on now).&amp;nbsp; What happens with the working one is my 802.1x SSID is configured for Dynamic VLAN (AAA Override) . On the controller I have a two user roles created that assign a VLAN pool to that role.&amp;nbsp; Also on the controller under Proxy Authentication where the settings for cloud path are I have the two attributes map to the user role.&amp;nbsp; The one I setup previously correctly assigns the VLAN pool and traffic policy.&amp;nbsp; The new one does not, the client ends up getting a DHCP address from the native vlan.&amp;nbsp; I have a feeling there is something I missed on the controller side but I can't find it.</description>
      <pubDate>Wed, 20 Feb 2019 00:25:31 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/VLAN-Pool-AAA-override/m-p/25392#M132</guid>
      <dc:creator>john_westlund</dc:creator>
      <dc:date>2019-02-20T00:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN Pool AAA override</title>
      <link>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/VLAN-Pool-AAA-override/m-p/25393#M133</link>
      <description>I just was on a call with support and they had me put the vlans in a list in the CloudPath cert template like in the attached screenshot.&lt;span class="lia-inline-image-display-wrapper" image-alt="Image_ images_messages_5f91c444135b77e2479f6875_4ffb2b4a8072e320552713589ae56f5d_RackMultipart20190221770155azu-11c70544-4e23-45ac-8f60-98e3e2633af5-1696472567.png1550779796"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/1753i07BA68F8F32A55F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_ images_messages_5f91c444135b77e2479f6875_4ffb2b4a8072e320552713589ae56f5d_RackMultipart20190221770155azu-11c70544-4e23-45ac-8f60-98e3e2633af5-1696472567.png1550779796" alt="Image_ images_messages_5f91c444135b77e2479f6875_4ffb2b4a8072e320552713589ae56f5d_RackMultipart20190221770155azu-11c70544-4e23-45ac-8f60-98e3e2633af5-1696472567.png1550779796" /&gt;&lt;/span&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;These are the two vlans that are in the pool assigned to the StaffBYOD user role.&amp;nbsp; The Filter ID is what I use to map to the user role in SZ100.&amp;nbsp; This user role has a traffic profile and vlan pool assigned to it and the traffic profile is being applied just not the vlan pool.&amp;nbsp; After adding this in Cloudpath it looks to me like all devices are getting an IP from vlan 730.&amp;nbsp; I have two other cert templates that use a different FilterID/User Role and they correctly apply the vlan pool without having to specify anything in Cloudpath for vlan ID.&amp;nbsp; I asked why those worked and this one doesn't but didn't get an answer.&amp;nbsp; I don't think the answer I got from support of adding the vlans in a list like this above is the answer.&amp;nbsp; Any ideas?</description>
      <pubDate>Thu, 21 Feb 2019 20:14:33 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/VLAN-Pool-AAA-override/m-p/25393#M133</guid>
      <dc:creator>john_westlund</dc:creator>
      <dc:date>2019-02-21T20:14:33Z</dc:date>
    </item>
  </channel>
</rss>

