ePMP with Radius authentication

Hi There,

I hope there’s some radius users here that might be willing to answer a few questions?

I’ve managed to get me ePMP3000 cpe’s to authenticate via Radius but I’ve been unsuccessful to pass a management IP plus Vlan back to the device in a similar fashion as I’m doing for our PMP450 network.

Radius seems to reply with the correct details via Authentication but the CPE seems unable to understand the Radius reply. Is this even possible with the ePMP series?

[ttls] Got tunneled reply code Access-Accept
Framed-IP-Address = 10.25.26.47
Framed-IP-Netmask = 255.255.255.0
Cambium-Canopy-Gateway = 10.25.26.254
Cambium-Canopy-VLIGVID = 20
Cambium-ePMP-ULMB = 800000
Cambium-ePMP-DLMB = 2200000

Thanks in advance,
-steph

You must set the management vlan first and this must be the same as the vlan used for radius authentication.
You must pass the correct VSA to do this:
Cambium-epmp-VLMGVID MANAGEMENT VLAN ID
Cambium-epmp-VLMG2VID SEPARATE MANAGEMENT VLAN ID
Cambium-epmp-VLMG2PID SEPARATE MANAGEMENT VLAN PRIORITY
Cambium-epmp-VLIGVID DATA VLAN ID
Cambium-epmp-VLDATAPID DATA VLAN PRIORITY

The radio MUST have these configured to something (no blank fields) and they must be enabled since VSAs only modify the existing config not replace it. If it is not configured then there is nothing to modify.

1 Like