Configuring Policy Maptable Response
22-52 Authentication and Authorization Configuration
Parameters
Defaults
Ifnoportstringisentered,thestatusforallportswillbedisplayed.
Mode
Switchcommand,read‐only.
Example
ThiscommandshowshowtodisplayVLANauthorizationstatusforge.1.1:
B5(su)->show vlanauthorization ge.1.1
Vlan Authorization: - enabled
port status administrative operational authenticated vlan id
egress egress mac address
------- -------- -------------- ----------- ----------------- -------
ge.1.1 enabled untagged
Table 22‐5providesanexplanationofcommandoutput.Fordetailsonenablingandassigning
protocolandegressattributes,referto“setvlanauthorization”onpage 22‐50and“set
vlanauthorizationegress”onpage 22‐50.
Configuring Policy Maptable Response
Thepolicymaptableresponsefeatureallowsyoutodefinehowthesystemshouldhandle
allowinganauthenticateduserontoaportbasedonthecontentsoftheRADIUSserverAccess‐
Acceptreply.Therearethreepossibleresponsesettings:tunnelmode,policymode,orbothtunnel
andpolicy,alsoknownashybrid
authenticationmode.
Whenthemaptable responseissettotunnelmode,thesystemwillusethetunnelattributesinthe
RADIUSreplytoapplyaVLANtotheauthenticatinguserandwillignoreanyFilter‐IDattributes
intheRADIUSreply.Onthisplatform,whentunnelmodeisconfigured,no
VLAN‐to‐policy
mappingwilloccur.WhenusingVLANauthorization,thepolicymaptableresponseshouldbeset
totunnel(see“ConfiguringVLANAuthorization(RFC3580)” onpage 22‐49).
port‐string (Optional)DisplaysVLANauthenticationstatusforthespecifiedports.If
noportstringisentered,thentheglobalstatusofthe
settingisdisplayed.
Foradetaileddescriptionofpossibleport‐stringvalues,referto“Port
StringSyntaxUsedintheCLI”onpage 7‐1.
Table 22-5 show vlanauthorization Output Details
Output Field What It Displays...
port Port identification
status Port status as assigned by set vlanauthorization command
administrative
egress
Port status as assigned by the set vlanauthorization egress command
operational egress Port operational status of vlanauthorization egress.
authenticated mac
address
If authentication has succeeded, displays the MAC address assigned for egress.
vlan id If authentication has succeeded, displays the assigned VLAN id for ingress.