EasyManua.ls Logo

Enterasys b5 - Operational Description

Enterasys b5
714 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Configuring Policy Maptable Response
Enterasys B5 CLI Reference 22-53
Whenthemaptableresponseissettopolicymode,thesystemwillusetheFilter‐IDattributesin
theRADIUSreplytoapplyapolicytotheauthenticatinguserandwillignoreanytunnel
attributesintheRADIUS reply.Onthisplatform,whenpolicymodeisconfigured,noVLAN‐to‐
policymappingwilloccur.
Whenthemaptableresponseissettoboth,orhybridauthenticationmode,bothFilter‐ID
attributes(dynamicpolicyassignment)andtunnelattribu tes(dynamicVLANassignment)sentin
RADIUSserverAccess‐Acceptrepliesareusedtodeterminehowtheswitchshouldhandle
authenticatingusers.Onthisplatform,when
hybridauthenticationmodeisconfigured,VLAN‐to‐
policymappingcanoccur,asdescribedbelowin“WhenPolicyMaptableResponseis“Both””on
page 22‐53.
UsinghybridauthenticationmodeeliminatesthedependencyonhavingtoassignVLANs
throughpolicyroles—VLANscanbeassignedbymeansofthetunnelattributes
whilepolicy
rolescanbeassignedbymeansoftheFilter‐IDattributes.Alternatively,VLAN‐to‐policymapping
canbeusedtomappoliciestousersusingtheVLANspecifiedbythetunnelattributes,without
havingtoconfigureFilter‐IDattributesontheRADIUSserver.Thisseparationgives
administratorsmore
flexibilityinsegmentingtheirnetworksbeyondtheplatform’shardware
policyrolelimits.
Referto“RADIUSFilter‐IDAttributeand DynamicPolicyProfileAssignment”onpage 22‐3for
moreinformationaboutFilter‐IDattributesand“ConfiguringVLANAuthorization(RFC3580)”
onpage 22‐49formoreinformationabouttunnelattributes.
Operational Description
When Policy Maptable Response is “Both”
HybridauthenticationmodeusesbothFilter‐IDattributesandtunnelattributes.Toenablehybrid
authenticationmode,usethesetpolicymaptablecommandandsettheresponseparameterto
both.Whenconfiguredtousebothsetsofattributes:
•IfboththeFilter‐IDandtunnelattributesarepresentintheRADIUSreply,
thenthepolicy
profilespecifiedbytheFilter‐IDisappliedtotheauthenticatinguser,andifVLAN
authorizationisenabledgloballyandonthe authenticatinguser’sport,theVLANspecifiedby
thetunnelattributesisappliedtotheauthenticatinguser.
IfVLANauthorizationisnotenabled,theVLANspecified
bythepolicy profileisapplied.See
“ConfiguringVLANAuthorization(RFC3580)”onpage 22‐49forinformationaboutenabling
VLANauthorizationgloballyandonspecificports.
•IftheFilter‐IDattributesarepresentbutthetunnelattributesarenotpresent,thepolicy
profilespecifiedbytheFilter‐IDisapplied,
alongwiththeVLANspecifiedbythepolicy
profile.
•IfthetunnelattributesarepresentbuttheFilter‐IDattributesarenotpresentorareinvalid,
andifVLANauthorizationisenabledgloballyandontheauthenticatinguser’sport,thenthe
switchwillchecktheVLAN‐to‐policymappingtable(configured
withthesetpolicy
maptablecommand):
–IfanentrymappingthereceivedVLANIDtoavalidpolicyprofileisfound,thenthat
policyprofile,alongwiththeVLANspecifiedbythepolicyprofile,willbeappliedtothe
authenticatinguser.
–Ifnomatchingmappingtableentryisfound,theVLANspecified
bythetunnelattributes
willbeappliedtotheauthenticatinguser.
–IftheVLAN‐to‐policymappingtableisinvalid,thenthe
etsysPolicyRFC3580MapInvalidMappingMIBisincrementedandtheVLANspecifiedby
thetunnelattributeswillbeappliedtotheauthenticatinguser.

Table of Contents