Configuring VLAN Authorization (RFC 3580)
D-Series CLI Reference 15-41
Parameters
Defaults
Ifnoauthenticationmethodisspecified,thesessiontimeoutvalueisresettoitsdefaultvalueof0
forallauthenticationmethods.
Mode
Switchmode,read‐write.
Example
ThisexampleresetsthesessiontimeoutvaluefortheIEEE802.1Xauthenticationmethodto0
seconds.
D2(su)->clear multiauth session-timeout dot1x
Configuring VLAN Authorization (RFC 3580)
Purpose
RFC3580TunnelAttributesprovideamechanismtocontainan802.1XauthenticatedoraMAC
authenticatedusertoaVLANregardlessofthePVID.
Pleaseseesection3‐31ofRFC3580fordetailsonconfiguringaRADIUSservertoreturnthe
desiredtunnelattributes.AsstatedinRFC3580,“...
itmaybedesirabletoallowaporttobeplaced
intoaparticularVirtualLAN(VLAN),definedin[IEEE8021Q],basedontheresultofthe
authentication.”
TheRADIUSservertypicallyindicatesthedesiredVLANbyincludingtunnelattributeswithinits
Access‐Acceptparameters.However,theIEEE802.1XorMACauthenticator
canalsobe
configuredtoinstructtheVLANtobeassignedtothesupplicantbyincludingtunnelattributes
withinAccess‐Requestparameters.
ThefollowingtunnelattributesareusedinVLANauthorizationassignment,:
•Tunnel‐Type‐VLAN(13)
•Tunnel‐Medium‐Type‐802
•Tunnel‐Private‐Group‐ID‐VLANID
InordertoauthenticatemultipleRFC3580
users,policymaptableresponsemustbesettotunnel
asdescribedinthissection.
dot1x (Op tional)SpecifiestheIEEE802.1Xport‐basednetworkaccesscontrol
authenticationmethodforwhichtoresetthetimeoutvaluetoits
default.
mac (Optional)SpecifiestheEnterasysMACauthenticationmethodfor
whichtoresetthetimeoutvalue
toitsdefault.
pwa (Optional)SpecifiestheEnterasysPortWebAuthenticationmethodfor
whichtoresetthetimeoutvaluetoitsdefault.
Note: The D2 cannot simultaneously support Policy and RFC 3580 on the same port. If multiple
users are configured to use a port, and the G3 is then switched from "policy" mode to (RFC-3580
"tunnel" mode, the total number of users supported to use a port will be reset to one.