Switch User Manual

Configuring Policy Maptable Response
SecureStack C3 Configuration Guide 26-53
Whenthemaptableresponseissettopolicymode,thesystemwillusetheFilterIDattributesin
theRADIUSreplytoapplyapolicytotheauthenticatinguserandwillignoreanytunnel
attributesintheRADIUS reply.Onthisplatform,whenpolicymodeisconfigured,noVLANto
policymappingwilloccur.
Whenthemaptableresponseissettoboth,orhybridauthenticationmode,bothFilterID
attributes(dynamicpolicyassignment)andtunnelattributes(dynamicVLANassignment)sentin
RADIUSserverAccessAcceptrepliesareusedtodeterminehowtheswitchshouldhandle
authenticatingusers.Onthisplatform,when
hybridauthenticationmodeisconfigured,VLANto
policymappingcanoccur,asdescribedbelowinWhenPolicyMaptableResponseis“Both”on
page 2653.
UsinghybridauthenticationmodeeliminatesthedependencyonhavingtoassignVLANs
throughpolicyrolesVLANscanbeassignedbymeansofthetunnelattributes
whilepolicy
rolescanbeassignedbymeansoftheFilterIDattributes.Alternatively,VLANtopolicymapping
canbeusedtomappoliciestousersusingtheVLANspecifiedbythetunnelattributes,without
havingtoconfigureFilterIDattributesontheRADIUSserver.Thisseparationgives
administratorsmore
flexibilityinsegmentingtheirnetworksbeyondtheplatform’shardware
policyrolelimits.
RefertoRADIUSFilterIDAttributeandDynamicPolicyProfileAssignmentonpage 263for
moreinformationaboutFilterIDattributesandConfiguring VLANAuthorization(RFC3580)
onpage 2649formoreinformationabouttunnelattributes.
Operational Description
When Policy Maptable Response is “Both”
HybridauthenticationmodeusesbothFilterIDattributesandtunnelattributes.Toenablehybrid
authenticationmode,usethesetpolicymaptablecommandandsettheresponseparameterto
both.Whenconfiguredtousebothsetsofattributes:
•IfboththeFilterIDandtunnelattributesarepresentintheRADIUSreply,
thenthepolicy
profilespecifiedbytheFilterIDisappliedtotheauthenticatinguser,andifVLAN
authorizationisenabledgloballyandontheauthenticatingusersport,theVLANspecifiedby
thetunnelattributesisappliedtotheauthenticatinguser.
IfVLANauthorizationisnotenabled,theVLANspecified
bythepolicyprofileisapplied.See
ConfiguringVLANAuthorization(RFC3580)onpage 2649 forinformationaboutenabling
VLANauthorizationgloballyandonspecificports.
•IftheFilterIDattributesarepresentbutthetunnelattributesarenotpresent,thepolicy
profilespecifiedbytheFilterIDisapplied,
alongwiththeVLANspecifiedbythepolicy
profile.
•IfthetunnelattributesarepresentbuttheFilterIDattributesarenotpresentorareinvalid,
andifVLANauthorizationisenabledgloballyandontheauthenticatingusersport,thenthe
switchwillchecktheVLANtopolicymappingtable(configured
withthesetpolicy
maptablecommand):
–IfanentrymappingthereceivedVLANIDtoavalidpolicyprofileisfound,thenthat
policyprofile,alongwiththeVLANspecifiedbythepolicyprofile,willbeappliedtothe
authenticatinguser.
–Ifnomatchingmappingtableentryisfound,theVLANspecified
bythetunnelattributes
willbeappliedtotheauthenticatinguser.
–IftheVLANtopolicymappingtableisinvalid,thenthe
etsysPolicyRFC3580MapInvalidMappingMIBisincrementedandtheVLANspecifiedby
thetunnelattributeswillbeappliedtotheauthenticatinguser.