EasyManuals Logo
Home>Enterasys>Other>b5

Enterasys b5 User Manual

Enterasys b5
714 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #637 background imageLoading...
Page #637 background image
Configuring VLAN Authorization (RFC 3580)
Enterasys B5 CLI Reference 22-49
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork(usingaRADIUS
FilterID).Whenthedefaultpolicyroleisassignedonaport,theVLANsetastheportʹsPVID
is
mappedtothedefaultpolicyrole.Whenapolicyroleisdynamicallyappliedtoauserastheresult
ofasuccessfullyauthenticatedsession,the“authenticatedVLAN”ismappedtothepolicyroleset
intheFilterIDreturnedfromtheRADIUSserver.The“authenticatedVLAN”mayeitherbe
the
PVIDoftheport,ifthePVIDOverrideforthepolicyprofileisdisabled,ortheVLANspecifiedin
thePVIDOverrideifthePVIDOverrideisenabled.
Configuring VLAN Authorization (RFC 3580)
Purpose
RFC3580TunnelAttributesprovideamechanismtocontainan802.1X,MAC,orPWA
authenticatedusertoaVLANregardlessofthePVID.ThisisreferredtoasdynamicVLAN
assignment.
Pleaseseesection331ofRFC3580fordetailsonconfiguringaRADIUSservertoreturnthe
desiredtunnel
attributes.AsstatedinRFC3580,“...itmaybedesirabletoallowaporttobeplaced
intoaparticularVirtualLAN(VLAN),definedin[IEEE8021Q],basedontheresultofthe
authentication.”
TheRADIUSservertypicallyindicatesthedesiredVLANbyincludingtunnelattributeswithinits
AccessAcceptparameters.
However,theIEEE802.1XorMACauthenticatorcanalsobe
configuredtoinstructtheVLANtobeassignedtothesupplicantbyincludingtunnelattributes
withinAccessRequestparameters.
ThefollowingtunnelattributesareusedinVLANauthorizationassignment:
•TunnelType‐VLAN(13)
•TunnelMediumType‐802
•TunnelPrivateGroupID‐VLANID
InordertoauthenticateRFC3580users,policymaptableresponsemustbesettotunnelas
describedinConfiguringPolicyMaptableResponseonpage 2252.
Commands
Note: A policy license, if applicable, is not required to deploy RFC 3580 dynamic VLAN
assignment.
For information about... Refer to page...
set vlanauthorization 22-50
set vlanauthorization egress 22-50
clear vlanauthorization 22-51
show vlanauthorization 22-51

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Enterasys b5 and is the answer not in the manual?

Enterasys b5 Specifications

General IconGeneral
BrandEnterasys
Modelb5
CategoryOther
LanguageEnglish