Switch User Manual

Configuring VLAN Authorization (RFC 3580)
SecureStack C3 Configuration Guide 26-49
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork(usingaRADIUS
FilterID).Whenthedefaultpolicyroleisassignedonaport,theVLANsetastheportʹsPVID
is
mappedtothedefaultpolicyrole.Whenapolicyroleisdynamicallyappliedtoauserastheresult
ofasuccessfullyauthenticatedsession,the“authenticatedVLAN”ismappedtothepolicyroleset
intheFilterIDreturnedfromtheRADIUSserver.The“authenticatedVLAN”mayeitherbe
the
PVIDoftheport,ifthePVIDOverrideforthepolicyprofileisdisabled,ortheVLANspecifiedin
thePVIDOverrideifthePVIDOverrideisenabled.
Configuring VLAN Authorization (RFC 3580)
Purpose
RFC3580TunnelAttributesprovideamechanismtocontainan802.1X,MAC,orPWA
authenticatedusertoaVLANregardlessofthePVID.ThisisreferredtoasdynamicVLAN
assignment.
Pleaseseesection331ofRFC3580fordetailsonconfiguringaRADIUSservertoreturnthe
desiredtunnel
attributes.AsstatedinRFC3580,“...itmaybedesirabletoallow aporttobeplaced
intoaparticularVirtualLAN(VLAN),definedin[IEEE8021Q],basedontheresultofthe
authentication.”
TheRADIUSservertypicallyindicatesthedesiredVLANbyincludingtunnelattributeswithinits
AccessAcceptparameters.
However,theIEEE802.1XorMACauthenticatorcanalsobe
configuredtoinstructtheVLANtobeassignedtothesupplicantbyincludingtunnelattributes
withinAccessRequestparameters.
ThefollowingtunnelattributesareusedinVLANauthorizationassignment:
•TunnelType‐VLAN(13)
•TunnelMediumType‐802
•TunnelPrivateGroupID‐VLANID
InordertoauthenticateRFC3580users,policymaptableresponsemustbesettotunnelas
describedinConfiguringPolicyMaptableResponseonpage 2652.
Commands
Note: A policy license, if applicable, is not required to deploy RFC 3580 dynamic VLAN
assignment.
For information about... Refer to page...
set vlanauthorization 26-50
set vlanauthorization egress 26-50
clear vlanauthorization 26-51
show vlanauthorization 26-51