Configuring Policy Maptable Response
Enterasys B5 CLI Reference 22-53
Whenthemaptableresponseissettopolicymode,thesystemwillusetheFilter‐IDattributesin
theRADIUSreplytoapplyapolicytotheauthenticatinguserandwillignoreanytunnel
attributesintheRADIUS reply.Onthisplatform,whenpolicymodeisconfigured,noVLAN‐to‐
policymappingwilloccur.
Whenthemaptableresponseissettoboth,orhybridauthenticationmode,bothFilter‐ID
attributes(dynamicpolicyassignment)andtunnelattribu tes(dynamicVLANassignment)sentin
RADIUSserverAccess‐Acceptrepliesareusedtodeterminehowtheswitchshouldhandle
authenticatingusers.Onthisplatform,when
hybridauthenticationmodeisconfigured,VLAN‐to‐
policymappingcanoccur,asdescribedbelowin“WhenPolicyMaptableResponseis“Both””on
page 22‐53.
UsinghybridauthenticationmodeeliminatesthedependencyonhavingtoassignVLANs
throughpolicyroles—VLANscanbeassignedbymeansofthetunnelattributes
whilepolicy
rolescanbeassignedbymeansoftheFilter‐IDattributes.Alternatively,VLAN‐to‐policymapping
canbeusedtomappoliciestousersusingtheVLANspecifiedbythetunnelattributes,without
havingtoconfigureFilter‐IDattributesontheRADIUSserver.Thisseparationgives
administratorsmore
flexibilityinsegmentingtheirnetworksbeyondtheplatform’shardware
policyrolelimits.
Referto“RADIUSFilter‐IDAttributeand DynamicPolicyProfileAssignment”onpage 22‐3for
moreinformationaboutFilter‐IDattributesand“ConfiguringVLANAuthorization(RFC3580)”
onpage 22‐49formoreinformationabouttunnelattributes.
Operational Description
When Policy Maptable Response is “Both”
HybridauthenticationmodeusesbothFilter‐IDattributesandtunnelattributes.Toenablehybrid
authenticationmode,usethesetpolicymaptablecommandandsettheresponseparameterto
both.Whenconfiguredtousebothsetsofattributes:
•IfboththeFilter‐IDandtunnelattributesarepresentintheRADIUSreply,
thenthepolicy
profilespecifiedbytheFilter‐IDisappliedtotheauthenticatinguser,andifVLAN
authorizationisenabledgloballyandonthe authenticatinguser’sport,theVLANspecifiedby
thetunnelattributesisappliedtotheauthenticatinguser.
IfVLANauthorizationisnotenabled,theVLANspecified
bythepolicy profileisapplied.See
“ConfiguringVLANAuthorization(RFC3580)”onpage 22‐49forinformationaboutenabling
VLANauthorizationgloballyandonspecificports.
•IftheFilter‐IDattributesarepresentbutthetunnelattributesarenotpresent,thepolicy
profilespecifiedbytheFilter‐IDisapplied,
alongwiththeVLANspecifiedbythepolicy
profile.
•IfthetunnelattributesarepresentbuttheFilter‐IDattributesarenotpresentorareinvalid,
andifVLANauthorizationisenabledgloballyandontheauthenticatinguser’sport,thenthe
switchwillchecktheVLAN‐to‐policymappingtable(configured
withthesetpolicy
maptablecommand):
–IfanentrymappingthereceivedVLANIDtoavalidpolicyprofileisfound,thenthat
policyprofile,alongwiththeVLANspecifiedbythepolicyprofile,willbeappliedtothe
authenticatinguser.
–Ifnomatchingmappingtableentryisfound,theVLANspecified
bythetunnelattributes
willbeappliedtotheauthenticatinguser.
–IftheVLAN‐to‐policymappingtableisinvalid,thenthe
etsysPolicyRFC3580MapInvalidMappingMIBisincrementedandtheVLANspecifiedby
thetunnelattributeswillbeappliedtotheauthenticatinguser.