EasyManuals Logo

Enterasys b5 User Manual

Enterasys b5
714 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #641 background imageLoading...
Page #641 background image
Configuring Policy Maptable Response
Enterasys B5 CLI Reference 22-53
Whenthemaptableresponseissettopolicymode,thesystemwillusetheFilterIDattributesin
theRADIUSreplytoapplyapolicytotheauthenticatinguserandwillignoreanytunnel
attributesintheRADIUS reply.Onthisplatform,whenpolicymodeisconfigured,noVLANto
policymappingwilloccur.
Whenthemaptableresponseissettoboth,orhybridauthenticationmode,bothFilterID
attributes(dynamicpolicyassignment)andtunnelattribu tes(dynamicVLANassignment)sentin
RADIUSserverAccessAcceptrepliesareusedtodeterminehowtheswitchshouldhandle
authenticatingusers.Onthisplatform,when
hybridauthenticationmodeisconfigured,VLANto
policymappingcanoccur,asdescribedbelowinWhenPolicyMaptableResponseis“Both”on
page 2253.
UsinghybridauthenticationmodeeliminatesthedependencyonhavingtoassignVLANs
throughpolicyrolesVLANscanbeassignedbymeansofthetunnelattributes
whilepolicy
rolescanbeassignedbymeansoftheFilterIDattributes.Alternatively,VLANtopolicymapping
canbeusedtomappoliciestousersusingtheVLANspecifiedbythetunnelattributes,without
havingtoconfigureFilterIDattributesontheRADIUSserver.Thisseparationgives
administratorsmore
flexibilityinsegmentingtheirnetworksbeyondtheplatform’shardware
policyrolelimits.
RefertoRADIUSFilterIDAttributeand DynamicPolicyProfileAssignmentonpage 223for
moreinformationaboutFilterIDattributesandConfiguringVLANAuthorization(RFC3580)
onpage 2249formoreinformationabouttunnelattributes.
Operational Description
When Policy Maptable Response is “Both”
HybridauthenticationmodeusesbothFilterIDattributesandtunnelattributes.Toenablehybrid
authenticationmode,usethesetpolicymaptablecommandandsettheresponseparameterto
both.Whenconfiguredtousebothsetsofattributes:
•IfboththeFilterIDandtunnelattributesarepresentintheRADIUSreply,
thenthepolicy
profilespecifiedbytheFilterIDisappliedtotheauthenticatinguser,andifVLAN
authorizationisenabledgloballyandonthe authenticatingusersport,theVLANspecifiedby
thetunnelattributesisappliedtotheauthenticatinguser.
IfVLANauthorizationisnotenabled,theVLANspecified
bythepolicy profileisapplied.See
ConfiguringVLANAuthorization(RFC3580)onpage 2249forinformationaboutenabling
VLANauthorizationgloballyandonspecificports.
•IftheFilterIDattributesarepresentbutthetunnelattributesarenotpresent,thepolicy
profilespecifiedbytheFilterIDisapplied,
alongwiththeVLANspecifiedbythepolicy
profile.
•IfthetunnelattributesarepresentbuttheFilterIDattributesarenotpresentorareinvalid,
andifVLANauthorizationisenabledgloballyandontheauthenticatingusersport,thenthe
switchwillchecktheVLANtopolicymappingtable(configured
withthesetpolicy
maptablecommand):
–IfanentrymappingthereceivedVLANIDtoavalidpolicyprofileisfound,thenthat
policyprofile,alongwiththeVLANspecifiedbythepolicyprofile,willbeappliedtothe
authenticatinguser.
–Ifnomatchingmappingtableentryisfound,theVLANspecified
bythetunnelattributes
willbeappliedtotheauthenticatinguser.
–IftheVLANtopolicymappingtableisinvalid,thenthe
etsysPolicyRFC3580MapInvalidMappingMIBisincrementedandtheVLANspecifiedby
thetunnelattributeswillbeappliedtotheauthenticatinguser.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Enterasys b5 and is the answer not in the manual?

Enterasys b5 Specifications

General IconGeneral
BrandEnterasys
Modelb5
CategoryOther
LanguageEnglish