Recently deployed Aruba Central to replace an old on prem Mobility Master/Conductor setup.
Our APs Tunnel to a Gateway.
We use a Radius server to control Access and use dynamic vlan assigned using named vlans for our corp network. We also provide a seperate SSID for another service and we point the SSID directly at their Radius servers with proxy the request to the users home radius server. For this SSID we use static vlan assignment.
The problem we have is that the radius access accept message is being received but rather than using our statically assigned vlan its attempting to drop the user into a non-existing vlan which then means the user fails to get an IP. Has anyone come across this before where dynamic vlan is overwriting a static vlan assignment even though we dont allow dynamic vlans?
We cant ask the service to remove the radius attribute because the radius proxy could be sent to anywhere up to 100 different orgs, i just need aruba to ignore it.