Configuring VLAN Authorization (RFC 3580)
Enterasys B5 CLI Reference 22-49
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork(usingaRADIUS
Filter‐ID).Whenthedefaultpolicyroleisassignedonaport,theVLANsetastheportʹsPVID
is
mappedtothedefaultpolicyrole.Whenapolicyroleisdynamicallyappliedtoauserastheresult
ofasuccessfullyauthenticatedsession,the“authenticatedVLAN”ismappedtothepolicyroleset
intheFilter‐IDreturnedfromtheRADIUSserver.The“authenticatedVLAN”mayeitherbe
the
PVIDoftheport,ifthePVIDOverrideforthepolicyprofileisdisabled,ortheVLANspecifiedin
thePVIDOverrideifthePVIDOverrideisenabled.
Configuring VLAN Authorization (RFC 3580)
Purpose
RFC3580TunnelAttributesprovideamechanismtocontainan802.1X,MAC,orPWA
authenticatedusertoaVLANregardlessofthePVID.ThisisreferredtoasdynamicVLAN
assignment.
Pleaseseesection3‐31ofRFC3580fordetailsonconfiguringaRADIUSservertoreturnthe
desiredtunnel
attributes.AsstatedinRFC3580,“...itmaybedesirabletoallowaporttobeplaced
intoaparticularVirtualLAN(VLAN),definedin[IEEE8021Q],basedontheresultofthe
authentication.”
TheRADIUSservertypicallyindicatesthedesiredVLANbyincludingtunnelattributeswithinits
Access‐Acceptparameters.
However,theIEEE802.1XorMACauthenticatorcanalsobe
configuredtoinstructtheVLANtobeassignedtothesupplicantbyincludingtunnelattributes
withinAccess‐Requestparameters.
ThefollowingtunnelattributesareusedinVLANauthorizationassignment:
•Tunnel‐Type‐VLAN(13)
•Tunnel‐Medium‐Type‐802
•Tunnel‐Private‐Group‐ID‐VLANID
InordertoauthenticateRFC3580users,policymaptableresponsemustbesettotunnelas
describedin“ConfiguringPolicyMaptableResponse”onpage 22‐52.
Commands
Note: A policy license, if applicable, is not required to deploy RFC 3580 dynamic VLAN
assignment.
For information about... Refer to page...
set vlanauthorization 22-50
set vlanauthorization egress 22-50
clear vlanauthorization 22-51
show vlanauthorization 22-51