Freeradius, Unifi and Vlans
Freeradius and Unifi Introduction When I joined my employer in 2012 i discovered they did something interesting called MAB which allowed the same switch port to put different vlans based on mac address. At the time I thought this was pretty interesting at it would allow me to have a guest vlan on my wireless access points. Having an old Cisco switch I setup something called VMPS using freeradius and a built in module called mac2vlan and I managed to set this up with pretty much no knowledge of radius. I stopped doing this as it really didn't work very well when a clients roamed between access points. Roaming between access points was still a problem so in time bit the bullet and bought expensive pro-consumer unifi access points. These could broadcast multiple sids and use different vlans. Roll on to the near past and IOT has arrived along with horrific security of devices. Spinning up lots of SIDs for each type of device is not possible (a limit of 4 per AP) and is j...