Specifications
Authentication Overview
April 15, 2011 Page 10 of 36
RFC 3580
EnterasysswitchessupporttheRFC3580RADIUStunnelattributefordynamicVLAN
assignment.TheVLAN‐Tunnel‐Attributeimplementstheprovisioningofserviceinresponsetoa
successfulau thentication.Onportsthatdonotsupportpolicy,thepacketwillbetaggedwiththe
VLAN‐ID.TheVLAN‐Tunnel‐Attributedefinesthebase
VLAN‐IDtobeappliedtothe user.
Dynamic VLAN Assignment
TheRADIUSservermayoptionallyincludeRADIUStunnelattributesinaRADIUS
Access‐AcceptmessagefordynamicVLANassignmentoftheauthenticatedendsystem.
RFC3580’sRADIUStunnelattributesare oftenconfiguredonaRADIUS servertodynamically
assignusersbelongingtothesameorganizationalgroupwithinanenterprisetothe
sameVLAN,
ortoplacealloffendingusersaccordingtotheorganization’ssecuritypolicyinaQuarantine
VLAN.Tunnelattributesaredeployedforenterprisesthathaveendsy stemauthentication
configuredonthenetwork.Forexample,allengineerscanbedynamicallyassignedtothesame
VLANuponauthentication,whilesalesareassigned
toanotherVLANuponauthentication.
ThenameofthefeatureonEnterasysplatformsthatimplementsdynamicVLANassignment
throughthereceiptofRADIUStunnelattributesisVLANauthorization.VLANauthorization
dependsuponreceiptoftheRFC3580RADIUStunnelattributesinRADIUSAccess‐Accept
messages.VLANauthorizationmustbeenabledglobally
andonaper‐portbasisfortheTunnel
attributestobeprocessed.Whendisabledperportorglobally,thedevicewillnotprocessTunnel
attributes.
ThefirmwaresupportsVLANauthorizationonthemodularswithches,stackablefixedswitches,
andstandalonefixedsw itches.
Bydefault,allpolicy‐capableEnterasysplatformswill
dynamicallyassignapolicyprofiletothe
portofanauthenticatinguserbasedonthereceiptoftheFilter‐IDRADIUSattribute.Thisisnot
thecasefor RADIUStunnelattributesinthat,bydefault,VLANauthorizationisdisabled.
TheN‐Series,startinginfirmwarerelease5.31.xx,theS‐Series,and
K‐Seriesplatformssupport
RFC3580RADIUSVLANTunnelattributes.
VLAN Authorization Attributes
ThreeTu nnelattributesareusedfordynamicVLANAuthorization:
•Tunnel‐Typeattribute(Type=64,Length=6,Tag=0,Value=0x0DforVLAN)
•Tunnel‐Medium‐Typeattribute(Type=65,Length=6,Tag=0,Value=0x06for802media)
•Tunnel‐Private‐Group‐IDattribute(Type=81,Length>=3 ,String=VIDinASCII)
TheTunnel‐Typeattributeindicatesthetunnelingprotocoltobeusedwhenthisattribute
is
formattedinRADIUSAccess‐Requestmessages,orthetunnelprotocolinusewhenthisattribute
isformattedinRADIUSAccess‐Acceptmessages.SetTunnel‐Typeattributeparametersas
follows:
•Type:Setto64forTunnel‐TypeRADIUSattribute
•Length:Setto6forsix‐bytelengthofthisRADIUSattribute
•Tag:
Providesameansofgroupingattributesinthesamepacketwhichrefertothesame
tunnel.Validvaluesforthisfieldarefrom0x01through0x1F,inclusive.Setto0ifunused.
Unlessalternativetunneltypesareprovided,itisonlynecessaryfortunnelattributesto
specifyasingletunnel.
Asaresult,whereitisonlydesiredtospecifytheVLAN‐ID,thetag
fieldshouldbesettozero(0x00)inalltunnelattributes.