Good afternoon, I have the following scenario, but I can't configure it
-
Hardware: cAP ax,
wifi-qcompackage, RouterOS 7.23.1 -
Scenario: WPA2-Enterprise with PEAP, authentication against Windows Server NPS (AD groups)
-
Objective: dynamically assign VLAN10 vs VLAN45 according to the AD group of the authenticated user
-
Confirmed that it works: NPS applies the correct policy (event 6272 verified), the fixed datapath works perfectly for static VLAN
-
Unsuccessful try: standard Tunnel-* attributes (RFC 2868), VSA Mikrotik-Wireless-VLANID in three encoding formats, datapath without vlan-id, Access List with vlan-id (without query-radius, which does not exist in this version)
-
Specific question: Is this mechanism possible in the EAP/PEAP flow with
wifi-qcom, or does it only apply to MAC authentication?