Hi Karol,
The KB procedure shared in previous post assigns one VLAN at a time to authenticated user. Whereas dynamic VLANs are not supported on trunk ports - see https://www.juniper.net/documentation/en_US/junos/topics/topic-map/802-1x-authentication-switching-devices.html
And the other link is about wired 802.1x example with Clearpass.
In your case, if you want to bridge/trunk VLANs from IAP and also authenticate the AP itself, then it's better to set up 802.1x authentication on EX for the IAP but not assign any VLAN. Then use 802.1x for wireless users and use either Aruba's dynamic VLAN or server rule with "Filter-Id" to assign a VLAN for authenticated user. There's plenty of resources for that in Aruba community, for example https://community.arubanetworks.com/t5/Controllerless-Networks/Setup-Dynamic-Vlans/td-p/91772.
Hope this helps.
Regards,
-r.
--------------------------------------------------
If this solves your problem, please mark this post as "Accepted Solution."
Kudos are always appreciated
.
The KB procedure shared in previous post assigns one VLAN at a time to authenticated user. Whereas dynamic VLANs are not supported on trunk ports - see https://www.juniper.net/documentation/en_US/junos/topics/topic-map/802-1x-authentication-switching-devices.html
And the other link is about wired 802.1x example with Clearpass.
In your case, if you want to bridge/trunk VLANs from IAP and also authenticate the AP itself, then it's better to set up 802.1x authentication on EX for the IAP but not assign any VLAN. Then use 802.1x for wireless users and use either Aruba's dynamic VLAN or server rule with "Filter-Id" to assign a VLAN for authenticated user. There's plenty of resources for that in Aruba community, for example https://community.arubanetworks.com/t5/Controllerless-Networks/Setup-Dynamic-Vlans/td-p/91772.
Hope this helps.
Regards,
-r.
--------------------------------------------------
If this solves your problem, please mark this post as "Accepted Solution."
Kudos are always appreciated
