Static vs. dynamic assignment
With static assignment, an administrator sets each port's VLAN (switchport access vlan 10). It's simple and predictable, but whoever plugs into that port lands in VLAN 10, and moving a person to another desk can mean a config change.
With dynamic assignment, the VLAN comes from who connects. Situation: employees and contractors share hot desks. Employees should land in VLAN 10, contractors in VLAN 50, whichever port they use.
What happens: 802.1X with RADIUS
- 1. Port is closed until login. The laptop (supplicant) sends its credentials or certificate to the switch using EAP over LAN.
- 2. Switch asks the server. The switch (authenticator) relays them to the RADIUS server.
- 3. Server decides. The user is an employee, so RADIUS answers Access-Accept with VLAN attributes saying VLAN 10.
- 4. Port placed in VLAN 10. The switch opens the port and puts it in VLAN 10. A contractor on the same port would get VLAN 50.
Why it works: the RADIUS Access-Accept carries three standard attributes that the switch understands:
| RADIUS attribute | Value |
|---|---|
| Tunnel-Type (64) | VLAN (13) |
| Tunnel-Medium-Type (65) | 802 (6) |
| Tunnel-Private-Group-ID (81) | The VLAN number or name, e.g. 10 |
The same idea works on Wi-Fi: users joining one SSID can be placed in different VLANs by identity.
Cisco configuration
aaa new-model
aaa authentication dot1x default group radius
aaa authorization network default group radius
dot1x system-auth-control
radius server CORP-RADIUS
address ipv4 192.168.99.10 auth-port 1812 acct-port 1813
key YOUR-SHARED-SECRET
interface GigabitEthernet1/0/5
switchport mode access
switchport access vlan 10
authentication port-control auto
dot1x pae authenticator'aaa authorization network' is what lets the switch apply the VLAN that RADIUS returns. The configured access VLAN is only used if RADIUS doesn't send one.
How to verify
SW1#show access-session interface Gi1/0/5 details Interface: GigabitEthernet1/0/5 MAC Address: 0200.0000.0010 User-Name: alice Status: Authorized ... Server Policies: Vlan Policy: 10 Method status list: Method State dot1x Authc Success
Don't confuse it with DTP
DTP (Dynamic Trunking Protocol) negotiates whether a port becomes a trunk. It has nothing to do with choosing a user's VLAN by identity, despite the "dynamic" in the name.
Practice
RADIUS accepts the user and sends VLAN attributes, but the user still lands in the port's configured VLAN 10 instead of VLAN 50.
A contractor moves from desk 12 to desk 30.