Home > Switches > Port and VLAN Configuration > Dynamic VLAN assignment via 802.1X (RADIUS) for MS Switches

Dynamic VLAN assignment via 802.1X (RADIUS) for MS Switches

Table of contents
No headers

It may be necessary to perform dynamic VLAN assignment on a per computer or per user basis. This can be done on your wired network via 802.1x authentication (RADIUS). In order to do so, the following RADIUS attributes must be configured and passed in the RADIUS Access-Accept message from the RADIUS server.


  • Tunnel-Medium-Type: Choose 802 (Includes all 802 media plus Ethernet canonical format) for the Attribute value Commonly used for 802.1X. 
  • Tunnel-Pvt-Group-ID: Choose String and enter the VLAN desired (ex. "500")This string will specify the VLAN ID 500.
  • Tunnel-Type: Choose  Attribute value Commonly used for 802.1X and select Virtual LANs (VLANs).


Once these attributes are configured on the RADIUS server, client devices can receive their VLAN assignment dynamically.

For more information on how to configure with NPS, visit Microsoft's article on Configuring a Network Policy for VLANs.

Last modified



This page has no classifications.

Explore the Product

Click to Learn More

Article ID

ID: 1144

Explore Meraki

You can find out more about Cisco Meraki on our main site, including information on products, contacting sales and finding a vendor.

Explore Meraki

Contact Support

Most questions can be answered by reviewing our documentation, but if you need more help, Cisco Meraki Support is ready to work with you.

Open a Case

Ask the Community

In the Meraki Community, you can keep track of the latest announcements, find answers provided by fellow Meraki users and ask questions of your own.

Visit the Community