- Enterasys Ethernet Switches Reference Manual

Configuring VLAN Authorization (RFC 3580)
D-Series CLI Reference 15-41
Parameters
Defaults
Ifnoauthenticationmethodisspecified,thesessiontimeoutvalueisresettoitsdefaultvalueof0
forallauthenticationmethods.
Mode
Switchmode,readwrite.
Example
ThisexampleresetsthesessiontimeoutvaluefortheIEEE802.1Xauthenticationmethodto0
seconds.
D2(su)->clear multiauth session-timeout dot1x
Configuring VLAN Authorization (RFC 3580)
Purpose
RFC3580TunnelAttributesprovideamechanismtocontainan802.1XauthenticatedoraMAC
authenticatedusertoaVLANregardlessofthePVID.
Pleaseseesection331ofRFC3580fordetailsonconfiguringaRADIUSservertoreturnthe
desiredtunnelattributes.AsstatedinRFC3580,“...
itmaybedesirabletoallowaporttobeplaced
intoaparticularVirtualLAN(VLAN),definedin[IEEE8021Q],basedontheresultofthe
authentication.”
TheRADIUSservertypicallyindicatesthedesiredVLANbyincludingtunnelattributeswithinits
AccessAcceptparameters.However,theIEEE802.1XorMACauthenticator
canalsobe
configuredtoinstructtheVLANtobeassignedtothesupplicantbyincludingtunnelattributes
withinAccessRequestparameters.
ThefollowingtunnelattributesareusedinVLANauthorizationassignment,:
•TunnelType‐VLAN(13)
•TunnelMediumType‐802
•TunnelPrivateGroupID‐VLANID
InordertoauthenticatemultipleRFC3580
users,policymaptableresponsemustbesettotunnel
asdescribedinthissection.
dot1x (Op tional)SpecifiestheIEEE802.1Xportbasednetworkaccesscontrol
authenticationmethodforwhichtoresetthetimeoutvaluetoits
default.
mac (Optional)SpecifiestheEnterasysMACauthenticationmethodfor
whichtoresetthetimeoutvalue
toitsdefault.
pwa (Optional)SpecifiestheEnterasysPortWebAuthenticationmethodfor
whichtoresetthetimeoutvaluetoitsdefault.
Note: The D2 cannot simultaneously support Policy and RFC 3580 on the same port. If multiple
users are configured to use a port, and the G3 is then switched from "policy" mode to (RFC-3580
"tunnel" mode, the total number of users supported to use a port will be reset to one.