Specifications

Authentication Overview
April 15, 2011 Page 10 of 36
RFC 3580
EnterasysswitchessupporttheRFC3580RADIUStunnelattributefordynamicVLAN
assignment.TheVLANTunnelAttributeimplementstheprovisioningofserviceinresponsetoa
successfulau thentication.Onportsthatdonotsupportpolicy,thepacketwillbetaggedwiththe
VLANID.TheVLANTunnelAttributedefinesthebase
VLANIDtobeappliedtothe user.
Dynamic VLAN Assignment
TheRADIUSservermayoptionallyincludeRADIUStunnelattributesinaRADIUS
AccessAcceptmessagefordynamicVLANassignmentoftheauthenticatedendsystem.
RFC3580’sRADIUStunnelattributesare oftenconfiguredonaRADIUS servertodynamically
assignusersbelongingtothesameorganizationalgroupwithinanenterprisetothe
sameVLAN,
ortoplacealloffendingusersaccordingtotheorganization’ssecuritypolicyinaQuarantine
VLAN.Tunnelattributesaredeployedforenterprisesthathaveendsy stemauthentication
configuredonthenetwork.Forexample,allengineerscanbedynamicallyassignedtothesame
VLANuponauthentication,whilesalesareassigned
toanotherVLANuponauthentication.
ThenameofthefeatureonEnterasysplatformsthatimplementsdynamicVLANassignment
throughthereceiptofRADIUStunnelattributesisVLANauthorization.VLANauthorization
dependsuponreceiptoftheRFC3580RADIUStunnelattributesinRADIUSAccessAccept
messages.VLANauthorizationmustbeenabledglobally
andonaperportbasisfortheTunnel
attributestobeprocessed.Whendisabledperportorglobally,thedevicewillnotprocessTunnel
attributes.
ThefirmwaresupportsVLANauthorizationonthemodularswithches,stackablefixedswitches,
andstandalonefixedsw itches.
Bydefault,allpolicycapableEnterasysplatformswill
dynamicallyassignapolicyprofiletothe
portofanauthenticatinguserbasedonthereceiptoftheFilterIDRADIUSattribute.Thisisnot
thecasefor RADIUStunnelattributesinthat,bydefault,VLANauthorizationisdisabled.
TheNSeries,startinginfirmwarerelease5.31.xx,theSSeries,and
KSeriesplatformssupport
RFC3580RADIUSVLANTunnelattributes.
VLAN Authorization Attributes
ThreeTu nnelattributesareusedfordynamicVLANAuthorization:
•TunnelTypeattribute(Type=64,Length=6,Tag=0,Value=0x0DforVLAN)
•TunnelMediumTypeattribute(Type=65,Length=6,Tag=0,Value=0x06for802media)
•TunnelPrivateGroupIDattribute(Type=81,Length>=3 ,String=VIDinASCII)
TheTunnelTypeattributeindicatesthetunnelingprotocoltobeusedwhenthisattribute
is
formattedinRADIUSAccessRequestmessages,orthetunnelprotocolinusewhenthisattribute
isformattedinRADIUSAccessAcceptmessages.SetTunnelTypeattributeparametersas
follows:
•Type:Setto64forTunnelTypeRADIUSattribute
•Length:Setto6forsixbytelengthofthisRADIUSattribute
•Tag:
Providesameansofgroupingattributesinthesamepacketwhichrefertothesame
tunnel.Validvaluesforthisfieldarefrom0x01through0x1F,inclusive.Setto0ifunused.
Unlessalternativetunneltypesareprovided,itisonlynecessaryfortunnelattributesto
specifyasingletunnel.
Asaresult,whereitisonlydesiredtospecifytheVLANID,thetag
fieldshouldbesettozero(0x00)inalltunnelattributes.