Switch User Manual

Configuring Policy Maptable Response
26-52 Authentication and Authorization Configuration
Parameters
Defaults
Ifnoportstringisentered,thestatusforallportswillbedisplayed.
Mode
Switchcommand,readonly.
Example
ThiscommandshowshowtodisplayVLANauthorizationstatusfor ge.1.1:
C3(su)->show vlanauthorization ge.1.1
Vlan Authorization: - enabled
port status administrative operational authenticated vlan id
egress egress mac address
------- -------- -------------- ----------- ----------------- -------
ge.1.1 enabled untagged
Table 265providesanexplanationofcommandoutput.Fordetailsonenablingandassigning
protocolandegressattributes,refertosetvlanauthorizationonpage 2650andset
vlanauthorizationegressonpage 2650.
Configuring Policy Maptable Response
Thepolicymaptableresponsefeatureallowsyoutodefinehowthesystemshould handle
allowinganauthenticateduserontoaportbasedonthecontentsoftheRADIUSserverAccess
Acceptreply.Therearethreepossibleresponsesettings:tunnelmode,policymode,orbothtunnel
andpolicy,alsoknownashybrid
authenticationmode.
Whenthemaptableresponseissettotunnelmode,thesystemwillusethetunnelattributesinthe
RADIUSreplytoapplyaVLANtotheauthenticatinguserandwillignoreanyFilterIDattributes
intheRADIUSreply.Onthisplatform,whentunnelmodeisconfigured,no
VLANtopolicy
mappingwilloccur.WhenusingVLANauthorization,thepolicymaptableresponseshouldbeset
totunnel(seeConfiguringVLANAuthorization(RFC3580)onpage 2649).
portstring (Optional)DisplaysVLANauthenticationstatusforthespecifiedports.If
noportstringisentered,thentheglobalstatusofthe
settingisdisplayed.
Foradetaileddescriptionofpossibleportstringvalues,refertoPort
StringSyntaxUsedintheCLIonpage 71.
Table 26-5 show vlanauthorization Output Details
Output Field What It Displays...
port Port identification
status Port status as assigned by set vlanauthorization command
administrative
egress
Port status as assigned by the set vlanauthorization egress command
operational egress Port operational status of vlanauthorization egress.
authenticated mac
address
If authentication has succeeded, displays the MAC address assigned for egress.
vlan id If authentication has succeeded, displays the assigned VLAN id for ingress.