EasyManua.ls Logo

Enterasys SecureStack C2 C2G170-24 - Set Vlanauthorization

Enterasys SecureStack C2 C2G170-24
698 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
set vlanauthorization
SecureStack C2 Configuration Guide 23-47
Whenausersuccessfullyauthenticatestothenetwork,theRADIUSserverreturnsanAccess
Acceptframe.Thisframecanhavemanyattributes,twoofwhichareaFilterID(whichishow
policyassignmentisachieved)andRFC3580VLANassignment.
Ifaswitchisintunnelmode:
•TheFID(FilterID)
isalwaysignored,butDefaultpolicyrulesstillapply.
•TheVLANattributeisusedifpresent,andifVLANauthorization isenabled.Seeset
vlanauthorizationonpage 2347.
Ifaswitchisinpolicymode:
•IftheAccessAcceptframehastheFIDattributeonly,thentheFIDisused.
•If
theAccessAcceptframehastheVLANattributeonly,thenitisusedprovidedthatVLAN
authorizationisenabled.Seesetvlanauthorizationonpage 2347.
•Ifbothattributesarereturned,usetheFIDonly.
Examples
Thisexampleshowshowtosetthepolicymaptableresponsetotunnel:
C2(rw)-> set policy maptable response tunnel
set vlanauthorization
EnableordisabletheuseoftheRADIUSVLANtunnelattributetoputaportintoaparticular
VLANbasedontheresultofauthentication.
Syntax
set vlanauthorization {enable | disable} [port-string]
Parameters
Defaults
VLANauthenticationisdisabledbydefault.
Mode
Switchcommand,readwrite.
Examples
ThisexampleshowshowtoenableVLANauthenticationforallGigabitEthernetports:
C2(rw)-> set vlanauthorization enable ge.*.*
ThisexampleshowshowtodisableVLANauthenticationforallGigabitEthernetportsonswitch
unit/module 3:
C2(rw)-> set vlanauthorization disable ge.3.*
enable|disable Enablesordisablesvlanauthorization/tunnelattributes.
portstring (Optional)SpecifieswhichportstoenableordisabletheuseofVLAN
tunnelattributes/authorization.Foradetaileddescriptionofpossibleport
stringvalues,refertoPortStringSyntaxUsedintheCLIonpage 72.

Table of Contents

Other manuals for Enterasys SecureStack C2 C2G170-24

Related product manuals