Skip to main content

Who can modify this feature?

  • Partner
  • Company Admin
  • Network Admin
  • Meter Support

What is a dynamic VLAN?

VLANs are used to segment types of network traffic—such as Private, Guest, and AV devices—from one another. Normally, one Wi-Fi SSID is tied to a single VLAN. With a Dynamic VLAN, an access point can assign a VLAN to each client as they connect, using only one Wi-Fi SSID.

Requirements

Dynamic VLANs require 802.1X authentication (RADIUS).
The RADIUS server must be configured to return a VLAN ID for each client when they authenticate.
Read more about pointing your Wi-Fi SSID to a RADIUS server here:
Network-wide → RADIUS Profiles (Adding 802.1X and WPA2-Enterprise)
The RADIUS server should set the following attributes for VLAN assignment:
Tunnel-Medium-Type = 6
Tunnel-Type = 13
Tunnel-Private-Group-Id = <VLAN_ID>
VLANs that can be assigned by the RADIUS server also need to exist on the Meter Security Appliance.
Learn more: Network-wide → VLANs

Configuring an SSID with a Dynamic VLAN

  1. Log in to the Dashboard.
  2. Navigate to Wireless → SSIDs → Add SSID.
  3. Under Security → Authentication, select any RADIUS-based security option.
  4. Toggle Dynamic VLAN to the desired mode.
Dynamic VLAN configuration Dynamic VLAN: Toggle this setting based on your use case.
Off: All devices using this SSID will be assigned to the selected VLAN.
On – Enabled: If no VLAN is specified by the RADIUS server, the system will use the fallback VLAN.
On – Required: If no VLAN is specified by the RADIUS server, the system will reject the client.
⚠️ Note:
Adding or removing an SSID that uses Dynamic VLAN authentication — even if the SSID is disabled — will trigger a reboot of all APs.
Schedule changes carefully to avoid unexpected disruptions.

Current limitations

The maximum VLAN count is 128 per access point. If you have any questions about Dynamic VLANs or need assistance, contact Meter Support at
support@meter.com or submit a ticket at dashboard.meter.com/support.
I