NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
Filis
Oct 16, 2021Aspirant
Orbi pro (SXK80) behind UDM router | Dynamic Vlan via radius
Dear community, dear Netgear Team,
I set up a UniFi UDM as a router with a radius server. Behind the UDM, I am running a Orbi Pro (SXK80 and a SXS80) on firmware 3.3.0.122 as an AP. The challenge is that I would like to dynamically assign a vlan to Orbi clients based on the radius authentication on the UDM.
For now, the authentication works, but the ips assigned to clients do not match the correct vlan address range, even though the tcpdump on the UDM indicates the right vlan in the accept message. so it seems the Orbi pro just doesn’t “understand” / “convert” / “translate” the radius reply correctly to its clients.
I found some documentation on dynamic vlan for other netgear products but non of it for the Orbi Pro. The configurations mentioned for other products (dynamic vlan, …) are not available in the Orbi pro Settings, so I cannot select anything but the radius ip, port and shared key.
If I select a vlan, only the selected address range is used, even if the radius credentials and the tcpdump would suggest a different address range.
How can I configure the Orbi Pro to dynamically select a vlan?
Thanks
6 Replies
- FilisAspirant
The tcpdump
21:46:58.681381 IP (tos 0x0, ttl 64, id 53332, offset 0, flags [none], proto UDP (17), length 221)
[ip address router].1812 > [ip address SXK80].44930: [udp sum ok] RADIUS, length: 193
Access-Accept (2), id: 0x17, Authenticator: [mac address]
Acct-Interim-Interval Attribute (85), length: 6, Value: 01:00:00 hours
0x0000: 0000 0e10
Tunnel-Type Attribute (64), length: 6, Value: Tag[Unused] VLAN
0x0000: 0000 000d
Tunnel-Medium-Type Attribute (65), length: 6, Value: Tag[Unused] 802
0x0000: 0000 0006
Tunnel-Private-Group-ID Attribute (81), length: 4, Value: 30
0x0000: 3330
User-Name Attribute (1), length: 11, Value: users
0x0000: [digits]
Vendor-Specific Attribute (26), length: 58, Value: Vendor: Microsoft (311)
Vendor Attribute: 17, Length: 50, Value: ..&...P...I..o.nd.^e.U...k1.d.[an..@lQ.........C..
0x0000: [8 blocks of 4 digits]
0x0010: [8 blocks of 4 digits]
0x0020: [8 blocks of 4 digits]
0x0030: [4 blocks of 4 digits]...
- schumakuGuru - Experienced User
- FilisAspirant
Thank you, schumaku.
I was hoping there is an option to do something like this with the UDM as a router and OrbiPro (SKX80) as a wifi access point?
https://www.downloads.netgear.com/files/answers/Dynamic%20VLAN%20Assignment%20using%20RADIUS.pdf
https://www.youtube.com/watch?v=l2ivHDIV50g
https://www.youtube.com/watch?v=AJcKsGtyfHo
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!