Security

 View Only
  • 1.  VLAN tags on Cisco CBS350 switch for access point port

    Posted Aug 03, 2025 12:41 PM
    Hello,
    Does anyone have experience with transferring VLAN tags to Cisco CBS 350 switches? I have done this quite often with Clearpass and Aruba cx switches, where it worked without any problems. The background is that a connected Sophos access point is to be placed untagged in VLAN 20 and then further VLANs are to be tagged. 
    VLAN 20 = 838860820
    VLAN 31 = 822083615
     
    I have attached a screenshot of the enforcement profile and the logs, which looks correct to me. However, the access point is not moved to VLAN 20 and VLAN 31 is not tagged.
     
    Does anyone have any tips or ideas on how I could solve this?
     
    THANK YOU
     


    -------------------------------------------


  • 2.  RE: VLAN tags on Cisco CBS350 switch for access point port

    Posted Aug 04, 2025 10:17 AM

    Sending HPE and/or Aruba RADIUS VSA to a Cisco product isn't going to work.  Have you looked at the Cisco documentation to see what is required?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: VLAN tags on Cisco CBS350 switch for access point port

    Posted Aug 04, 2025 02:00 PM

    Not so easy to find a documentation about the used radius attributes on this cisco switch model

    -------------------------------------------



  • 4.  RE: VLAN tags on Cisco CBS350 switch for access point port

    Posted Aug 04, 2025 02:19 PM

    A quick Google of "cisco cbs350 radius dynamic vlan" gave quite a few hits, looks like they use the standard IETF attributes.

    YouTube video on the subject: https://youtu.be/pzjjuBq4cSo?si=-v9n3_Umjm3TN_T1

    Questionable if there is support for tagged and untagged returns.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: VLAN tags on Cisco CBS350 switch for access point port

    Posted Aug 04, 2025 02:35 PM

    Thank but this does not really help me because untagged vlans are working. But nut taggged vlans 

    -------------------------------------------



  • 6.  RE: VLAN tags on Cisco CBS350 switch for access point port
    Best Answer

    Posted Aug 04, 2025 02:43 PM

    I found out that the CBS350 switch does not support vlan tags from radius

    Thanks for your help

    -------------------------------------------