Except for dot1x are the client assignment today to based on the physical port in the access switch.

If we could move that assignment to the network outlet instead and combined it with a service description where we store more information regarding the client's connection request then could we do the following tasks easily.

In the picture are there three types of connections to the network, where the direct line is how we do it today and the extra orange box how it could be if we created a service definition layer.


  1. Client that gets a vlan based on it's MAC-address an the port it's connected to. Assigned via Radius. 
  2. Client that gets a vlan or template based only on the port it's connected to. Assigned via NMS
  3. Client that gets a vlan based on the profile of the device.

Our network inventory could be a perfect place to store that type of service description. That would mean that NAV for example should talk to the inventory and put the service template on the outlet instead of the switch. The radius admin also need to create calls to the inventory.