Administrator Guide

Table Of Contents
Authentication, Authorization, and Accounting 325
3 - CHAP-Password - = Encrypted MAC address (CHAP) only or
unencrypted (PAP) User Name
4 - NAS-IP-Address IP address of the switch
5 - NAS-Port switch internal port number (ifIndex)
6 - Service Type is set to 10 for MAB (Call-Check)
12 - Framed-MTU - port/switch MTU - header length (e.g. 1500)
30 - Called Station ID MAC address of device (in xx:xx:xx:xx:xx:xx format)
31 - Calling Station ID Switch MAC address
60 - CHAP Challenge (CHAP only)
61 - NAS-Port-Type (Ethernet 15)
80 - Message Authenticator
87 - NAS-Port-ID
What is the Role of 802.1X in VLAN Assignment?
Dell EMC Networking N-Series switches allow a port to be placed into a
particular VLAN based on the result of the authentication. The
authentication server can provide information to the switch about which
VLAN to assign the supplicant or the administrator can configure the level of
access provided when authentication fails or is never attempted.
When a host connects to a switch that uses an authentication server to
authenticate, the host authentication will have one of three outcomes:
The host is authenticated.
The host attempts to authenticate but fails because it lacks certain
security credentials.
The host does not try to authenticate at all (802.1X unaware).
Three separate VLANs can be created on the switch to handle a host
depending on whether the host authenticates, fails the authentication, or
does not attempt authentication. The RADIUS server informs the switch of
the selected VLAN as part of the authentication.
NOTE: MAB initiates only after the dot1x guest VLAN period times out. If the client
responds to any of the EAPOL identity requests, MAB does not initiate for that
client.