It's totally possible to change the tagged vlan. Just write a radius filter
and use EGRESS-VLANID

On Mon, Nov 18, 2019, 11:05 AM Sajawal Ghani via PacketFence-users <
[email protected]> wrote:

> Thanks for your reply.
>
> The problem is, I can assign role 'reject' only after the radius has sent
> an access-accept response. My end device sends tagged packets and as soon
> as radius response is accept the device goes into forwarding mode
> regardless that the radius server assigns a registration VLAN or 'reject
> role'. Since the VLAN is tagged it is not possible to influence it.
> Therefore, I wanted to ask if there is a way that the radius server can
> send response reject at the first place so the port doesn't allow any
> device to go into forwarding mode.
> Regards,
> Sajawal Ghani
> Network Engineer
> _________________________________
>
> iternas GmbH
> Niederlassung Stuttgart
> Mobil: +49 172 894 52 77
> Hauptsitz:
>
> iternas GmbH
>
> Pappelallee 78/79
>
> 10437 Berlin
>
> Tel:    +49 30 609 800 24-0
>
> E-Mail: [email protected]
> Web: http://www.iternas.com
>
> Amtsgericht Berlin (Charlottenburg), HRB 204123 B
> Geschäftsführer: Morris Görke
> _______________________________________________
> PacketFence-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to