Hello,
Does anybody know if radius authentication with an external radius servers works with the new drivers wifi-qcom-ac 7.13 to allocate different vlans to clients? My setup worked very well on V6 with capsman. Currently and trying to do the same on 7.13 and struggling to make it work. Read about the issues with vlan assignments but not sure if this affects radius authentication also. At the moment just trying to make one AP work with wifi radius authentication beforing adding capsman. With wpa2-psk i manage to make the configuration work with an untagged vlan.
Your setup isn’t possible when running wave2/wifi drivers. The new driver doesn’t handle VLAN tags natively (neither per user set by radius or ACLs nor static set as datapath property).
We’re quite a large group of users hoping and waiting for this support to get added.
Could you elaborate please? I am a RouterOS newbie. I am asking because I think I have something like OP wants working.
My current setup is one CRS-323 (currently on SwitchOS) and two cAP-ax running wifi-qcom. I have dynamic vlan assignment working with WPA2-EAP, without capsman for now. The clients are authenticated against a FreeRadius running on a pfsense, which also tells the APs which VLAN each client belongs to. What I am struggling with is to do dynamic VLAN assignment with wifi-qcom and WPA2-PSK by MAC address. But I asked about that in a different topic.
Apologies I clicked on the solved button by accident. Based on my testing of the latest beta version and the changelog it’s not yet resolved still waiting.
I’ve bought Mikrotik cAP ax, hoping that everything would just work as before on previous models (currently I have hAP-Ac-2 and hAP-mini) – I need to replace AP from my ISP.
Started to configure RADIUS authentication today and figured out there are no “Security Profiles” anymore and the “Security” tab doesn’t have RADIUS option at all
This is really bad user experience and apparently the issue is almost 1 year old. Subscribed to the topic to get updates.
Cap ax works with wifi radius authentication. I use an external radius and it s fine. Older models like cap ac do not yet because of the driver. If you want to use miikrotik radius it’s a different package that needs to be installed and setup.
I guess the RADIUS authentication is not the issue in my case. I want to have per MAC VLAN tagging using external RADIUS server. And this feature seems to be unsupported. Or do I miss something?
I don’t see a VLAN ID configuration on Wireless settings anywhere :-/
I have no idea how this integrates with the optional (!) on-device RADIUS server called User Manager, available as user-manager-*.npk in the extra packages archive, much less with third-party RADIUS servers.