It's totally possible to change the tagged vlan. Just write a radius filter and use EGRESS-VLANID
On Mon, Nov 18, 2019, 11:05 AM Sajawal Ghani via PacketFence-users < [email protected]> wrote: > Thanks for your reply. > > The problem is, I can assign role 'reject' only after the radius has sent > an access-accept response. My end device sends tagged packets and as soon > as radius response is accept the device goes into forwarding mode > regardless that the radius server assigns a registration VLAN or 'reject > role'. Since the VLAN is tagged it is not possible to influence it. > Therefore, I wanted to ask if there is a way that the radius server can > send response reject at the first place so the port doesn't allow any > device to go into forwarding mode. > Regards, > Sajawal Ghani > Network Engineer > _________________________________ > > iternas GmbH > Niederlassung Stuttgart > Mobil: +49 172 894 52 77 > Hauptsitz: > > iternas GmbH > > Pappelallee 78/79 > > 10437 Berlin > > Tel: +49 30 609 800 24-0 > > E-Mail: [email protected] > Web: http://www.iternas.com > > Amtsgericht Berlin (Charlottenburg), HRB 204123 B > Geschäftsführer: Morris Görke > _______________________________________________ > PacketFence-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/packetfence-users >
_______________________________________________ PacketFence-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/packetfence-users
