Switch User Manual
Configuring Policy Maptable Response
26-52 Authentication and Authorization Configuration
Parameters
Defaults
Ifnoportstringisentered,thestatusforallportswillbedisplayed.
Mode
Switchcommand,read‐only.
Example
ThiscommandshowshowtodisplayVLANauthorizationstatusfor ge.1.1:
C3(su)->show vlanauthorization ge.1.1
Vlan Authorization: - enabled
port status administrative operational authenticated vlan id
egress egress mac address
------- -------- -------------- ----------- ----------------- -------
ge.1.1 enabled untagged
Table 26‐5providesanexplanationofcommandoutput.Fordetailsonenablingandassigning
protocolandegressattributes,referto“setvlanauthorization”onpage 26‐50and“set
vlanauthorizationegress”onpage 26‐50.
Configuring Policy Maptable Response
Thepolicymaptableresponsefeatureallowsyoutodefinehowthesystemshould handle
allowinganauthenticateduserontoaportbasedonthecontentsoftheRADIUSserverAccess‐
Acceptreply.Therearethreepossibleresponsesettings:tunnelmode,policymode,orbothtunnel
andpolicy,alsoknownashybrid
authenticationmode.
Whenthemaptableresponseissettotunnelmode,thesystemwillusethetunnelattributesinthe
RADIUSreplytoapplyaVLANtotheauthenticatinguserandwillignoreanyFilter‐IDattributes
intheRADIUSreply.Onthisplatform,whentunnelmodeisconfigured,no
VLAN‐to‐policy
mappingwilloccur.WhenusingVLANauthorization,thepolicymaptableresponseshouldbeset
totunnel(see“ConfiguringVLANAuthorization(RFC3580)” onpage 26‐49).
port‐string (Optional)DisplaysVLANauthenticationstatusforthespecifiedports.If
noportstringisentered,thentheglobalstatusofthe
settingisdisplayed.
Foradetaileddescriptionofpossibleport‐stringvalues,referto“Port
StringSyntaxUsedintheCLI”onpage 7‐1.
Table 26-5 show vlanauthorization Output Details
Output Field What It Displays...
port Port identification
status Port status as assigned by set vlanauthorization command
administrative
egress
Port status as assigned by the set vlanauthorization egress command
operational egress Port operational status of vlanauthorization egress.
authenticated mac
address
If authentication has succeeded, displays the MAC address assigned for egress.
vlan id If authentication has succeeded, displays the assigned VLAN id for ingress.