© Copyright Lenovo 2017 Chapter 6: 802.1X Port-Based Network Access Control 119
81 Tunnel‐Private‐
Group‐ID
VLANID(1‐4094).When
802.1XRADIUSVLAN
assignmentisenabledonaport,
iftheRADIUSserverincludes
thetunnelattributesdefinedin
RFC2868intheAccess‐Accept
packet,theswitchwill
automaticallyplacethe
authenticatedportinthe
specifiedVLAN.Reserved
VLANs(suchas
for
management)maynotbe
specified.Theattributemustbe
untagged(theTagfieldmust
be 0).
00‐10 0
79 EAP‐Message EncapsulatedEAPpacketsfrom
thesupplicanttothe
authenticationserver(Radius)
andvice‐versa.The
authenticatorrelaysthe
decodedpackettobothdevices.
1+ 1+ 1+ 1+
80 Message‐
Authenticator
Alwayspresentwheneveran
EAP‐Messageattributeis
also
included.Usedto
integrity‐protectapacket.
1111
87 NAS‐Port‐ID Nameassignedtothe
authenticatorport,e.g.
Server1_Port3
1000
Legend:RADIUSPacketTypes:A‐R (Access‐Request),A‐A(Access‐Accept),
A‐C (Access‐Challenge),A‐R(Access‐Reject)
RADIUSAttributeSupport:
0ThisattributeMUSTNOTbepresentinapacket.
0+ ZeroormoreinstancesofthisattributeMAYbepresentinapacket.
0‐1ZerooroneinstanceofthisattributeMAYbepresentinapacket.
1ExactlyoneinstanceofthisattributeMUSTbepresentinapacket.
1+ OneormoreoftheseattributesMUSTbepresent.
Table 11.
SupportforRADIUSAttributes(continued)
# Attribute Attribute Value A-R A-A A-C A-R