EasyManua.ls Logo

Enterasys b5

Enterasys b5
714 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Configuring Policy Maptable Response
Enterasys B5 CLI Reference 22-53
Whenthemaptableresponseissettopolicymode,thesystemwillusetheFilterIDattributesin
theRADIUSreplytoapplyapolicytotheauthenticatinguserandwillignoreanytunnel
attributesintheRADIUS reply.Onthisplatform,whenpolicymodeisconfigured,noVLANto
policymappingwilloccur.
Whenthemaptableresponseissettoboth,orhybridauthenticationmode,bothFilterID
attributes(dynamicpolicyassignment)andtunnelattribu tes(dynamicVLANassignment)sentin
RADIUSserverAccessAcceptrepliesareusedtodeterminehowtheswitchshouldhandle
authenticatingusers.Onthisplatform,when
hybridauthenticationmodeisconfigured,VLANto
policymappingcanoccur,asdescribedbelowinWhenPolicyMaptableResponseis“Both”on
page 2253.
UsinghybridauthenticationmodeeliminatesthedependencyonhavingtoassignVLANs
throughpolicyrolesVLANscanbeassignedbymeansofthetunnelattributes
whilepolicy
rolescanbeassignedbymeansoftheFilterIDattributes.Alternatively,VLANtopolicymapping
canbeusedtomappoliciestousersusingtheVLANspecifiedbythetunnelattributes,without
havingtoconfigureFilterIDattributesontheRADIUSserver.Thisseparationgives
administratorsmore
flexibilityinsegmentingtheirnetworksbeyondtheplatform’shardware
policyrolelimits.
RefertoRADIUSFilterIDAttributeand DynamicPolicyProfileAssignmentonpage 223for
moreinformationaboutFilterIDattributesandConfiguringVLANAuthorization(RFC3580)
onpage 2249formoreinformationabouttunnelattributes.
Operational Description
When Policy Maptable Response is “Both”
HybridauthenticationmodeusesbothFilterIDattributesandtunnelattributes.Toenablehybrid
authenticationmode,usethesetpolicymaptablecommandandsettheresponseparameterto
both.Whenconfiguredtousebothsetsofattributes:
•IfboththeFilterIDandtunnelattributesarepresentintheRADIUSreply,
thenthepolicy
profilespecifiedbytheFilterIDisappliedtotheauthenticatinguser,andifVLAN
authorizationisenabledgloballyandonthe authenticatingusersport,theVLANspecifiedby
thetunnelattributesisappliedtotheauthenticatinguser.
IfVLANauthorizationisnotenabled,theVLANspecified
bythepolicy profileisapplied.See
ConfiguringVLANAuthorization(RFC3580)onpage 2249forinformationaboutenabling
VLANauthorizationgloballyandonspecificports.
•IftheFilterIDattributesarepresentbutthetunnelattributesarenotpresent,thepolicy
profilespecifiedbytheFilterIDisapplied,
alongwiththeVLANspecifiedbythepolicy
profile.
•IfthetunnelattributesarepresentbuttheFilterIDattributesarenotpresentorareinvalid,
andifVLANauthorizationisenabledgloballyandontheauthenticatingusersport,thenthe
switchwillchecktheVLANtopolicymappingtable(configured
withthesetpolicy
maptablecommand):
–IfanentrymappingthereceivedVLANIDtoavalidpolicyprofileisfound,thenthat
policyprofile,alongwiththeVLANspecifiedbythepolicyprofile,willbeappliedtothe
authenticatinguser.
–Ifnomatchingmappingtableentryisfound,theVLANspecified
bythetunnelattributes
willbeappliedtotheauthenticatinguser.
–IftheVLANtopolicymappingtableisinvalid,thenthe
etsysPolicyRFC3580MapInvalidMappingMIBisincrementedandtheVLANspecifiedby
thetunnelattributeswillbeappliedtotheauthenticatinguser.

Table of Contents