Dynamic VLAN with EAP 783

Dynamic VLAN with EAP 783

21 Reply
Re:Dynamic VLAN with EAP 783-Solution
2025-07-12 12:02:30 - last edited 2025-07-18 01:57:05

  @relvy Hello,

 

With help from the TP-Link Support the root problem has been found:

I use freeradius to do EAP-TTLS+PAP and offload PAP to a radius proxy belonging to my IdP (authentik).
As described in https://www.freeradius.org/documentation/freeradius-server/3.2.8/tutorials/eap-ttls.html the Access-Accept packet shall contain MPPE keys and the EAP-Message but that was not the case for me.

Why?
Because the radius proxy did not return any attributes.

 

Solution: I reconfigured freeradius to use ldap authentication belonging to my IdP (authentik).

Then I got the MPPE keys and the EAP-Message in the Access-Accept packet.

 

Then dynamic VLAN assignment works. Mobile Phone, Macbook's etc. can connect the SSID and access the network and internet.

 

Recommended Solution
  0  
  0  
#22
Options