Assigning Multiple VLANs for WAP Switch Ports Using RADIUS

Assigning Multiple VLANs for WAP Switch Ports Using RADIUS

Assigning Multiple VLANs for WAP Switch Ports Using RADIUS
Assigning Multiple VLANs for WAP Switch Ports Using RADIUS
2025-09-03 05:36:56 - last edited 2025-09-09 15:33:53
Model: TL-SG3428X  
Hardware Version: V1
Firmware Version: 1.30.4 Build 20250121 Rel.50059

Hello, all. I'm trying to figure out a way to apply multiple tagged VLANs to switch ports that I have wireless access points connected to. Here's the desired outcome (I think it's reasonably straightforward):

    I plug an AP into any random port on the switch
    The switch calls out to a Windows NPS server to authenticate the AP
    The NPS server tells the switch to set the management VLAN as untagged while setting VLANS associated with SSIDs to tagged


I've gotten so far as to get dynamic VLAN assignment working for a single VLAN. What I'm stuck on is getting the port to accept multiple VLAN assignments from the RADIUS server. Does anyone know if this is even possible using Omada? I've tried an assortment of different syntaxes for the tunnel private group ID string on the NPS side ('vlan_id1 vlan_id2', 'vlan_id1;vlan_id2', etc) but nothing I've tried works. I'm really grasping at straws at this point.


We have a very similar configuration where I work, but it's a much larger environment with much more sophisticated equipment. The TP-Link gear is just for my house.


-Newb

  0      
  0      
#1
Options
5 Reply
Re:Assigning Multiple VLANs for WAP Switch Ports
2025-09-03 07:40:59 - last edited 2025-09-03 07:42:20

  @NewbAdmin 

The RADIUS is not necessary for your home setup. This might go in the wrong direction. 

RADIUS is about the AAA authentication, authorization, and accounting.

If you simply need a trunk, which is the term for multiple VLAN on a single port, you could configure it as a VLAN trunk on the ports.

See the guide: 

How to Configure VLAN on TP-Link Switch

Common Questions About 802.1Q VLAN

 

Management VLAN can coexist with other VLANs. That's a different guide:

How to configure Management VLANs for Omada Switches and APs (for Business scenario)

  0  
  0  
#2
Options
Re:Assigning Multiple VLANs for WAP Switch Ports
2025-09-03 16:04:15

  @Clive_A Thanks for the response. I really appreciate the time you took to offer feedback. However, I'm not asking if it is necessary; I'm asking if it is possible. A big part of the purpose of my home environment is to gain practical experience, and I'm modeling it as closely as I can after an enterprise environment.

 

I have static trunks set up where absolutely necessesary. A static trunk is not necessary for an AP since none of my other infrastructure depends on it to stay up.

 

I bounced this off of one of the infra guys at work, and he said there's no reason this wouldn't work unless the vendor doesn't support it, or unless I have some misconfiguration or am missing something. Does the vendor support it?

 

-Newb

  0  
  0  
#3
Options
Re:Assigning Multiple VLANs for WAP Switch Ports
2025-09-04 02:44:52

  @NewbAdmin 

If you ask me if this switch supports RADIUS, and dynamic VLAN, yes, it does.

Configuration Guide on Dynamic VLAN with the VLAN Assignment function of RADIUS

  0  
  0  
#4
Options
Re:Assigning Multiple VLANs for WAP Switch Ports
2025-09-04 04:11:36

  @Clive_A I have successfully configured dynamic VLAN assignment for 1 VLAN at a time, but that's only part-way to my end goal. I also need to be able to set additional tagged VLAN IDs that are associated with SSIDs the APs host.

 

The end result should look like this port that I set up manually (see below), but I haven't had any success getting the same result using NPS.

---------------------------------------------

 PVID: 6
 Acceptable frame type: All
 Ingress Checking: Enable
 Member in LAG: N/A
 Link Type: General
 Member in VLAN:
 Vlan    Name            Egress-rule
 ----      -----------         -----------
 6         N/A                Untagged
 30       N/A                Tagged
 20       N/A                Tagged

---------------------------------------------

Will the switch and/or Omada accept/interpret multiple VLAN IDs from the RADIUS server? Again, the goal is for me to be able to plug in an AP to any random port on the switch and let RADIUS do all the work of setting up the link between the switch and the AP. That includes putting the AP on the management VLAN and ensuring all traffic from the wireless networks is able to traverse that link. As you put it earlier, I am trying to set up a trunk link. I just don't want to do it manually any time I need/want to move an AP to another port.

 

I hope that adds some clarity.

 

-Newb

 

 

  0  
  0  
#5
Options
Re:Assigning Multiple VLANs for WAP Switch Ports
2025-09-11 18:10:35

  @Clive_A 

 

I guess I'll take another go at clarifying what I'm trying to do.

 

I'm asking if there is a supported syntax for the Tunnel-Private-Group-ID (RADIUS attribute 81) that will allow an Omada switch to dynamically assign multiple simultaneous tagged VLANS to a switch port.

 

I checked in with the Ubiquiti community forum to see how UniFi products handled this sort of thing. They very concisely told me that UniFi doesn't support this. Is that true for Omada as well?

 

-Newb

  0  
  0  
#6
Options