A RADIUS server has the ability to send VLAN information to the AP in RADIUS Access Accept messages. To send VLAN information, three required RADIUS attributes must be configured in your RADIUS policy:
Sample freeRADIUS user configuration (/etc/freeradius/users):
Tunnel-Medium-Type = 6, Tunnel-Private-Group-ID = [VLAN_ID], Tunnel-Type = VLAN
Note: According to RFC 2868, a value of "6" for Tunnel-Medium-Type denotes all 802 media. Check your RADIUS vendor-specific documentation for the appropriate values.
To configure the AP to accept the VLAN information sent from by the RADIUS server, enable set "Radius Override" to "RADIUS Response Can Override VLAN tag." This setting can override the configured SSID VLAN or apply a VLAN if one is not specified: