Packet mangling with RADIUS

I wanted to offer tiered service (hotspot, wireless gateway) based on the user’s profile but it seems that I cannot do this if I use RADIUS as my authentication mechanism. Is there another solution?

2nd that. Mangle rules using radius would be neat.

We configure all our AP’s using Virtual AP’s. The default AP has no authentication, but dumps everyone to a hotspot enabled interface. Then we create other VirtualAP’s which authenticate RADIUS, with unique SSID’s, and dont have Hot spot enable on interface. Works great. We have “arialink-hotspot” “arialink-voip” “arialink-dynamicip” “arialink-staticip”

You get the idea.

I forgot to mention, since its interface related, you can apply the mangle rules to the interface and only distinguish services by having subscriber associate with the service’s ssid