You are here: Roles and Policies > Configuring Derivation Rules > Configuring a User Role for VLAN Derivation
Previous TopicNext Topic

Configuring a User Role for VLAN Derivation

This section describes the following procedures:

Creating a User VLAN Role
Assigning User VLAN Roles to a Network Profile

Creating a User VLAN Role

You can create a user role for VLAN derivation using the Instant UI or CLI

In the Instant UI

To configure a user role for VLAN derivation:

1. Click the Security at the top right corner of Instant main window.
2. Click the Roles tab. The Roles tab contents are displayed.
3. Under Roles, click New.
4. Enter a name for the new role and click OK.
5. Under the Access rules, click New.
6. Select the Rule type as VLAN assignment.
7. Enter the ID of the VLAN in the VLAN ID text box.
8. Click OK.

In the CLI

To create a VLAN role:

(Instant AP)(config)# wlan access-rule <rule-name>

(Instant AP)(Access Rule <rule-name>)# vlan 200

(Instant AP)(Access Rule <rule-name>)# end

(Instant AP)# commit apply

Assigning User VLAN Roles to a Network Profile

You can configure user VLAN roles for a network profile using Instant UI or CLI.

In the Instant UI

To assign a user VLAN role:

1. Click Network > New > New WLAN > Access or Network > edit > Edit <WLAN-profile> > Access.
2. Ensure that the slider is at the Role-based option.
3. Click New under the New Role Assignment and configure the following parameters:
a. Select the attribute from the Attribute drop-down list.
b. Select the operator to match from the Operator drop-down list.
c. Enter the string to match in the String text box.
d. Select the role to be assigned from the Role text box. The following figure shows an example for the VLAN role assignment:

Figure 1  User VLAN Role Assignment

4. Click OK.

In the CLI

To assign VLAN role to a WLAN profile:

(Instant AP)(config)# wlan ssid-profile <name>

(Instant AP)(SSID Profile <name>)# set-role <attribute>{{equals <operator> <role>| not-equals <operator> <role>| starts-with <operator> <role>| ends-with <operator> <role>| contains <operator> <role>}|value-of}

(Instant AP)(SSID Profile <name>)# end

(Instant AP)# commit apply