NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Filis's avatar
Filis
Aspirant
Oct 16, 2021

Orbi pro (SXK80) behind UDM router | Dynamic Vlan via radius

Dear community, dear Netgear Team,

 

I set up a UniFi UDM as a router with a radius server. Behind the UDM, I am running a Orbi Pro (SXK80 and a SXS80) on firmware 3.3.0.122 as an AP. The challenge is that I would like to dynamically assign a vlan to Orbi clients based on the radius authentication on the UDM.

 

For now, the authentication works, but the ips assigned to clients do not match the correct vlan address range, even though the tcpdump on the UDM indicates the right vlan in the accept message. so it seems the Orbi pro just doesn’t “understand” / “convert” / “translate” the radius reply correctly to its clients.

 

I found some documentation on dynamic vlan for other netgear products but non of it for the Orbi Pro. The configurations mentioned for other products (dynamic vlan, …) are not available in the Orbi pro Settings, so I cannot select anything but the radius ip, port and shared key.

 

If I select a vlan, only the selected address range is used, even if the radius credentials and the tcpdump would suggest a different address range.

 

How can I configure the Orbi Pro to dynamically select a vlan?

 

Thanks

6 Replies

  • The tcpdump

     

    21:46:58.681381 IP (tos 0x0, ttl 64, id 53332, offset 0, flags [none], proto UDP (17), length 221)
    [ip address router].1812 > [ip address SXK80].44930: [udp sum ok] RADIUS, length: 193
    Access-Accept (2), id: 0x17, Authenticator: [mac address]
    Acct-Interim-Interval Attribute (85), length: 6, Value: 01:00:00 hours
    0x0000: 0000 0e10
    Tunnel-Type Attribute (64), length: 6, Value: Tag[Unused] VLAN
    0x0000: 0000 000d
    Tunnel-Medium-Type Attribute (65), length: 6, Value: Tag[Unused] 802
    0x0000: 0000 0006
    Tunnel-Private-Group-ID Attribute (81), length: 4, Value: 30
    0x0000: 3330
    User-Name Attribute (1), length: 11, Value: users
    0x0000: [digits]
    Vendor-Specific Attribute (26), length: 58, Value: Vendor: Microsoft (311)
    Vendor Attribute: 17, Length: 50, Value: ..&...P...I..o.nd.^e.U...k1.d.[an..@lQ.........C..
    0x0000: [8 blocks of 4 digits]
    0x0010: [8 blocks of 4 digits]
    0x0020: [8 blocks of 4 digits]
    0x0030: [4 blocks of 4 digits]

    ...

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More