Need to roll out dynamic port configuration on the Juniper EX switch., require to use of Egress-VLAN-Name attribute sent from ClearPass
dot1xd[00000]: DOT1XD_USR_SESSION_HELD: MAC-RADIUS User 482567350efe session with MacAddress 00-00-00-AA-BB-CC interface ge-0/0/0.0 vlan (null) is held
dot1xd[00000: DOT1XD_USR_SESSION_HELD: MAC-RADIUS User 482567350efe session with MacAddress 00-00-00-AA-BB-CC interface ge-0/0/0.0 vlan (null) is held
Reconfigured ClearPass to use Tunnel-Pvt-Group-ID with the VLAN name as the value, instead of Egress-VLAN-Name/ID, and this was successful in permitting multiple supplicants on the same port while still having the flexibility of assigning VLANs by name.
Also consider that pre-configured port profile on Juniper EX switches is the recommended approach for dynamic trucking on AP ports.
Colorless ports are used in conjunction with device profiling with any standards-based radius server, and convert an access port to a trunk port and allow the necessary VLANs with necessary tagging. In the case that some of the VLAN’s are missing on the switch, this feature helps in creating those missing VLANs dynamically on the switch.
https://www.juniper.net/documentation/us/en/software/nce/nce-209-ex-aruba-device-profiling/topics/example/nce-209-configuring-colorless-ports-ex-aruba-clearpass-policy.html