radius authentication with vLan

Hi all,
i am facing some issue. Recently we purchased a Mobile Controller from HP. We would like to deploy Wireless Accesspoint using authentication from Radius server.

The thing is:
1. my server ip is: 172.16.1.1
2. my boss would like to separate between Internal User and remote users UNDER 1 SSID! using different vlan.

so meaning, if internal user logs in (authenticate successfully, they get the correct IP address 172.16.1.x). If remote users from branch office visit our office. They authenticate and they must get another subnet 192.168.1.x where they can go online and mustnt able to browse network shares (security reason).

please advise how do i work it out.
julisantoAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

araberuniCommented:
I am starting from no 2. you need two ssid. one for internal users (vlan 172.16.1.x ) and other for guest users (valn 192.168.1.x )

You can assign IP range in Radius server for Guest Users or both or you can have IP addresses from internal DHCP server by setting up IP helper address and assign IP from internal network. your radius server should be placed in internal network (vlan 172.16.1.x ). WAPs should be in vlan 172.16.1.x and 192.168.1.x networks.

Here are how to if you need just in case.
http://microsoftguru.com.au/2010/04/30/complete-guide-to-build-a-cisco-wireless-infrastructure-using-cisco-wlc-5500-cisco-1142-ap-and-microsoft-radius-server/
http://microsoftguru.com.au/2009/08/02/how-to-configure-cisco-1242-ap-to-get-authentication-from-ms-ias/
http://microsoftguru.com.au/2009/08/17/microsoft-radius-server-ias-apple-imacmacbook-pro-osx-10-5-and-xp-pro-step-by-step/
http://microsoftguru.com.au/2009/11/11/windows-server-2008-how-to-configure-network-policy-server-nps-or-radius-server/

All these article apply for Cisco WLC, Cisco WAP, win2k8 NPS, win2k3 IAS server and any clients. Please let me know whether this helps.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Wireless Networking

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.