Switch User Manual
Configuring VLAN Authorization (RFC 3580)
SecureStack C3 Configuration Guide 26-49
Thesecondpolicyrole,fortheuser,caneitherbestaticallyconfiguredwiththedefaultpolicyrole
ontheportordynamicallyassignedthroughauthenticationtothenetwork(usingaRADIUS
Filter‐ID).Whenthedefaultpolicyroleisassignedonaport,theVLANsetastheportʹsPVID
is
mappedtothedefaultpolicyrole.Whenapolicyroleisdynamicallyappliedtoauserastheresult
ofasuccessfullyauthenticatedsession,the“authenticatedVLAN”ismappedtothepolicyroleset
intheFilter‐IDreturnedfromtheRADIUSserver.The“authenticatedVLAN”mayeitherbe
the
PVIDoftheport,ifthePVIDOverrideforthepolicyprofileisdisabled,ortheVLANspecifiedin
thePVIDOverrideifthePVIDOverrideisenabled.
Configuring VLAN Authorization (RFC 3580)
Purpose
RFC3580TunnelAttributesprovideamechanismtocontainan802.1X,MAC,orPWA
authenticatedusertoaVLANregardlessofthePVID.ThisisreferredtoasdynamicVLAN
assignment.
Pleaseseesection3‐31ofRFC3580fordetailsonconfiguringaRADIUSservertoreturnthe
desiredtunnel
attributes.AsstatedinRFC3580,“...itmaybedesirabletoallow aporttobeplaced
intoaparticularVirtualLAN(VLAN),definedin[IEEE8021Q],basedontheresultofthe
authentication.”
TheRADIUSservertypicallyindicatesthedesiredVLANbyincludingtunnelattributeswithinits
Access‐Acceptparameters.
However,theIEEE802.1XorMACauthenticatorcanalsobe
configuredtoinstructtheVLANtobeassignedtothesupplicantbyincludingtunnelattributes
withinAccess‐Requestparameters.
ThefollowingtunnelattributesareusedinVLANauthorizationassignment:
•Tunnel‐Type‐VLAN(13)
•Tunnel‐Medium‐Type‐802
•Tunnel‐Private‐Group‐ID‐VLANID
InordertoauthenticateRFC3580users,policymaptableresponsemustbesettotunnelas
describedin“ConfiguringPolicyMaptableResponse”onpage 26‐52.
Commands
Note: A policy license, if applicable, is not required to deploy RFC 3580 dynamic VLAN
assignment.
For information about... Refer to page...
set vlanauthorization 26-50
set vlanauthorization egress 26-50
clear vlanauthorization 26-51
show vlanauthorization 26-51