300-430 · Question #223
A request has come in to use dynamic VLAN assignment on an autonomous AP. After the AP is configured, which RADIUS attribute must an engineer use to pass the VLAN ID to the AP?
The correct answer is B. Tunnel-Private-Group-ID. Dynamic VLAN assignment requires three RADIUS tunnel attributes; the VLAN ID or name itself is carried specifically in Tunnel-Private-Group-ID (attribute 81).
Question
A request has come in to use dynamic VLAN assignment on an autonomous AP. After the AP is configured, which RADIUS attribute must an engineer use to pass the VLAN ID to the AP?
Options
- ATunnel-Medium-Type
- BTunnel-Private-Group-ID
- CTunnel-Assignment-ID
- DTunnel-Type
How the community answered
(23 responses)- A4% (1)
- B87% (20)
- C9% (2)
Why each option
Dynamic VLAN assignment requires three RADIUS tunnel attributes; the VLAN ID or name itself is carried specifically in Tunnel-Private-Group-ID (attribute 81).
Tunnel-Medium-Type (attribute 65) specifies the transport medium - set to '802' for IEEE 802 Ethernet networks - but does not carry the VLAN ID itself.
Tunnel-Private-Group-ID (RADIUS attribute 81) is the attribute that carries the actual VLAN ID or VLAN name to be assigned to the authenticating client. While Tunnel-Type and Tunnel-Medium-Type are also required in the full attribute set, Tunnel-Private-Group-ID is the one that directly passes the VLAN identifier to the AP for assignment.
Tunnel-Assignment-ID is not part of the standard RADIUS attribute set used for dynamic VLAN assignment and is not recognized by Cisco autonomous APs for this purpose.
Tunnel-Type (attribute 64) is required and set to 'VLAN' to indicate the tunneling protocol type, but it defines the tunnel type rather than the actual VLAN identifier.
Concept tested: RADIUS tunnel attributes for dynamic VLAN assignment
Source: https://www.cisco.com/c/en/us/support/docs/wireless/aironet-1200-series/44784-VLAN-assign.html
Topics
Community Discussion
No community discussion yet for this question.