Routelearn.net
Course menu

Course 4: VLANs and TrunksLesson 1.3 (3 of 7 in this course)11 of 91 in the CCNA series

Dynamic VLAN assignment

Choosing a device's VLAN from who is connecting, not which port they plugged into.

Intermediate · 6 min read · Before this: VLAN

Dynamic VLAN assignment is a method of placing a switch port in a VLAN according to the identity of the user or device that connects, rather than a fixed port configuration. Typically the device authenticates with 802.1X and the RADIUS server returns the VLAN to use in its Access-Accept message.

In simple terms: Instead of the switch port deciding which network you join, who you are decides. You land in the same VLAN whichever socket you plug into.

Static vs. dynamic assignment

With static assignment, an administrator sets each port's VLAN (switchport access vlan 10). It's simple and predictable, but whoever plugs into that port lands in VLAN 10, and moving a person to another desk can mean a config change.

With dynamic assignment, the VLAN comes from who connects. Situation: employees and contractors share hot desks. Employees should land in VLAN 10, contractors in VLAN 50, whichever port they use.

What happens: 802.1X with RADIUS

Employee laptopsupplicantSwitchauthenticatorRADIUS serverauthentication server
  1. 1. Port is closed until login. The laptop (supplicant) sends its credentials or certificate to the switch using EAP over LAN.
  2. 2. Switch asks the server. The switch (authenticator) relays them to the RADIUS server.
  3. 3. Server decides. The user is an employee, so RADIUS answers Access-Accept with VLAN attributes saying VLAN 10.
  4. 4. Port placed in VLAN 10. The switch opens the port and puts it in VLAN 10. A contractor on the same port would get VLAN 50.

Why it works: the RADIUS Access-Accept carries three standard attributes that the switch understands:

RADIUS attributeValue
Tunnel-Type (64)VLAN (13)
Tunnel-Medium-Type (65)802 (6)
Tunnel-Private-Group-ID (81)The VLAN number or name, e.g. 10

The same idea works on Wi-Fi: users joining one SSID can be placed in different VLANs by identity.

Cisco configuration

aaa new-model aaa authentication dot1x default group radius aaa authorization network default group radius dot1x system-auth-control radius server CORP-RADIUS address ipv4 192.168.99.10 auth-port 1812 acct-port 1813 key YOUR-SHARED-SECRET interface GigabitEthernet1/0/5 switchport mode access switchport access vlan 10 authentication port-control auto dot1x pae authenticator

'aaa authorization network' is what lets the switch apply the VLAN that RADIUS returns. The configured access VLAN is only used if RADIUS doesn't send one.

How to verify

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show access-session interface Gi1/0/5 details
            Interface:  GigabitEthernet1/0/5
          MAC Address:  0200.0000.0010
            User-Name:  alice
               Status:  Authorized
...
Server Policies:
          Vlan Policy:  10

Method status list:
       Method           State
        dot1x           Authc Success
Status: Authorized and dot1x Authc Success show the login worked; Vlan Policy: 10 is the VLAN RADIUS assigned.

Don't confuse it with DTP

DTP (Dynamic Trunking Protocol) negotiates whether a port becomes a trunk. It has nothing to do with choosing a user's VLAN by identity, despite the "dynamic" in the name.

Practice

Predict · scenario 1

RADIUS accepts the user and sends VLAN attributes, but the user still lands in the port's configured VLAN 10 instead of VLAN 50.

Predict · scenario 2

A contractor moves from desk 12 to desk 30.