VLAN Wireless Access

Source: Internet
Author: User

As more and more companies launch their wireless networks, people are most concerned about how to connect wireless users to appropriate wired VLANs. VLAN user identities in a wired network are usually defined by the user's Physical Layer 2 switch or Layer 3 router connection port. However, in a wireless network, the user does not connect to any physical port at all.

Advanced wireless authentication technology, and role-based VLAN Association for user identification. This method can use a series of standard authentication methods, such as HTTP capture port and 802.1x based optional authentication mechanism to determine the correct VLAN user identity.


We can assume a scenario. A finance department wireless user may need to Securely connect to the finance VLAN, using a secure link encryption method, such as Wi-Fi Protected Access. However, when users in this VLAN roam to other access points, they may no longer be able to access the financial VLAN and thus cannot obtain the required network resources. If you need to reconfigure the network and enable users to access VLAN at every access point in the company, the entire reconfiguration process will become very complicated, of course, it is impossible to become a competitive solution.

However, 802.1x port-based authentication can provide an effective framework for users on Ethernet and wireless networks to grant Base Station access authorization. 802.1x uses the Extensible Authentication Protocol (EAP) to relay access requests between LAN base station Requestor), Ethernet switches, or Wireless Access Point validators) and RADIUS server verification servers.

The core mechanism used to protect Wi-Fi network users is based on data encryption and user authentication, rather than the role-based authentication method. Role-based 802.1x VLAN Association is very attractive because it provides reasonable work group Traffic segmentation and is easier to integrate with the Security and Traffic Engineering policies configured on the wired network.

Network administrators usually want to keep the original extended service set IDESSID for all users) and encrypted files. In this way, when a user enters the wireless LAN, the system can allocate the user to different working groups in different VLANs Based on the configured properties on the verification server. If you do not use a role-based VLAN, this method is basically impossible, unless many configurations of the wireless LAN are adjusted one by one, and a new ESSID is introduced for each user group. This operation will undoubtedly require huge capital investment and high operating costs.

Wireless LAN switches support various types of user roles, as well as different access permissions and VLAN associations. It also supports multiple types of server rules and extends user roles, such as the RADIUS attribute in the access acceptance information sent by the RADIUS server. For example, a server rule is used to extract a value from a specific RADIUS attribute and use this value as the role. In 802.1x authentication, the client authenticates to the radius server through a wireless LAN switch. Then, the wireless LAN establishes an association between the VLAN and the client based on the role generated after the Server rule is executed.

Once the connection with the access point is established, the wireless LAN switch places the client in an unauthorized state. In this status, only the 802.1x EAP Packet Generated by the client can be forwarded through the wireless LAN. The wireless LAN switch sends an EAP Request-ID, that is, the user identity Request information to the client. The client responds to an EAP Response-ID message. Then, the wireless LAN switch packets the EAP Response-ID as a RADIUS access request and forwards it to the RADIUS server.

If the verification succeeds, the RADIUS server sends the access acceptance information to the wireless LAN switch. This information identifies different user attributes, such as roles and access permissions. Then, the wireless LAN switch will parse the response and determine the VLAN to which the client should be allocated.

With this information, the wireless LAN switch places the client under authorization and sends an EAP Success message. After that, the switch forwards all data traffic from the client to the appropriate VLAN. After receiving the EAP Success information, the client starts the Dynamic Host Configuration Protocol and obtains an IP address from the role-based VLAN.


Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.