Specifications

Authentication Overview
April 15, 2011 Page 11 of 36
Value:Indicatesthetypeoftunnel.Avalueof0x0D(decimal13)indicatesthatthe tunneling
protocolisaVLAN.
TunnelMediumTypeindicatesthetransportmediumtousewhencreatingatunnelforthe
tunnelingprotocol,determinedfromTunnelTypeattribute.SetTunnelMediumTypeattribute
parametersasfollows:
•Type:Set
to65forTunnelMediumTypeRADIUSattribute
•Length:Setto6forsixbytelengthofthisRADIUSattribute
•Tag:Providesameansofgroupingattributesinthesamepacketwhichrefertothesame
tunnel.Validvalueforthisfieldare0x01through0x1F,inclusive.Setto0if
unused.Unless
alternativetunneltypesareprovided,itisonlynecessaryfortunnelattributestospecifya
singletunnel.Asaresult,whereitisonlydesiredtospecifytheVLANID,thetagfieldshould
besettozero(0x00)inalltunnelattributes.
Value:Indicatesthetypeoftunnel.A
valueof0x06indicatesthatthetunnelingmedium
pertainsto802media(includingEthernet)
TunnelPrivateGroupIDattributeindicatesthegroupIDforaparticulartunneledsession.Setthe
TunnelPrivateGroupIDattributeparametersasfollows:
•Type:Setto81forTunnelPrivateGroupIDRADIUSattribute
•Length:Setto
avaluegreaterthanorequalto3.
•Tag:Providesameansofgroupingattributesinthesamepacketwhichrefertothesame
tunnel.Validvaluesforthisfieldarefrom0x01through0x1F,inclusive.Setto0ifunused.
Unlessalternativetunneltypesareprovided,itisonlynecessary
fortunnelattributesto
specifyasingletunnel.Asaresult,whereitisonlydesiredtospecifytheVLANID,the tag
fieldshouldbesettozero(0x00)inalltunnelattributes.
•String:Indicatesthegroup.FortheVLANIDintegervalue,itisencodedasastringusing
ASCII.
Forexample,theVLANIDintegervalue103wouldberepresentedas0x313033
VLAN Authorization Considerations
VLANAuthorizationposessomeoperationalandmanagementissuesonthenetwork.
•AVLANisnotasecuritycontainer.Itisabroadcastcontainerandusedtosegmentbroadcast
trafficonthenetwork.ACLsimplementedatthelayer3routedinterfaceforaVLANonly
provideaccesscontrolfortrafficintoand
outoftheVLAN.Noaccesscontrolmechanismfor
intraVLANcommunicationsexists,thereforeuserswithintheVLANarenotprotectedfrom
eachother.MalicioustrafficallowedontoaVLANcanpotentiallyinfectalltrafficonthe
VLAN.Suchaninfectioncanconsumevaluablehardwareresourcesontheinfra stru c ture,
suchas
CPUcyclesandmemory.Infectionscanbetransmittedtootherhostswithinthe
VLANandtothelayer3routedboundary.Thisleadstothedirectcompetitionofmalicious
trafficwithbusinesscriticaltrafficonthenetwork.
•EndToEndQoScannotbetrulyguaranteedifQoSisimplementedatthe
layer3routed
interfaceforanetworkwherebusinesscriticalapplicationsareclassifiedandprioritized.
•IfVLANsareimplementedtogrouptogetherusersthataremembersofthesame
organizationalgroup,thenaVLANmustbeconfiguredeverywhereinthenetworktopology
whereamemberofthatorganizationalunitmay
connecttothenetwork.Forexample,ifan
engineermayconnecttothenetworkfromanylocation,thentheEngineeringVLANmustbe
configuredonallaccesslayerdevicesinthenetwork.TheseVLAN configurationsleadto
overextendedbroadcastdomainsaswellasaddedconfiguration complexityinthenetwork
topology.