Specifications

Authentication Overview
April 15, 2011 Page 12 of 36
•AproblemwithmovinganendsystemtoanewVLANisthattheendsystemmustbeissued
anIPaddressonthenewVLANssubnettowhichithasbecomeamember.Iftheendsystem
doesnotyethaveanIPaddress,thisisnotusuallyaproblem.
However,iftheendsystemhas
anIPaddress,theleaseoftheaddressmusttimeoutbeforeitattemptstoobtainanew
address,whichmaytakesometime.TheIPaddressassignmentprocess,implementedby
DHCP,andtheauthenticationprocessarenotconjoinedontheendsystem.Therefore,
this
leadstoendsystemspossessinganinvalidIPaddressafterdynamicVLANAu thorizationand
lostIPconnectivityuntilitscurrentIPaddresstimesout.Furthermore,whenanewIPaddress
iseventuallyassignedtotheendsystem,IPconnectivityisdisruptedforallapplicationson
theendsystem.
Policy Maptable Response
Thepolicymaptableresponse,orconflictresolution,featureallowsyoutodefinehowthesystem
shouldhandleallowinganauthenticateduserontoaportbasedonthecontentsoftheRADIUS
Acceptmessagereply.Therearethreepossibleresponsesettings:tunnelmode,policymode,or
bothtunnelandpolicy,alsoknown
ashybridauthenticationmode.
Whenthemaptableresponseissettotunnelmode,thesystemwillusethetunnelattributesinthe
RADIUSreplytoapplyaVLANtotheauthenticatinguserandwillignoreanyFilterIDattributes
intheRADIUSreply.Whentunnelmodeisconfigured,VLANtopolicy
mappingcanoccurif
configuredonamodularswitchplatform.VLANtopolicymappingwillnotoccurintunnel
modeonastackablefixedswitchorstandalonefixedswitchplatform.
Whenthemaptableresponseissettopolicymode,thesystemwillusetheFilterIDattributesin
theRADIUS
replytoapplyapolicytotheauthenticatinguserandwillignoreanytunnel
attributesintheRADIUS reply.Whenpolicymodeisconfigured,noVLANtopolicymapping
willoccur.
Whenthemaptableresponseissettoboth,orhybridauthenticationmode,bothFilterID
attributes(dynamicpolicyassignment)and
tunnelattributes(dynamicVLANassignment)sentin
RADIUSAcceptmessagerepliesareusedtodeterminehowtheswitchshouldhandle
authenticatingusers.Whenhybridauthenticationmodeisconfigured,VLANtopolicymapping
canoccur,asdescribedbelowinWhenPolicyMaptableResponseis“Both”.
Usinghybridauthenticationmodeeliminatesthe
dependencyonhavingtoassignVLANs
throughpolicyrolesVLANscanbeassignedbymeansofthetunnelattribu teswhilepolicy
rolescanbeassignedbymeansoftheFilterIDattributes.Alternatively,onmodularswitch
platforms,VLANtopolicymappingcanbeusedtomappoliciestousersusing
theVLAN
specifiedbythetunnelattributes,withouthavingtoconfigureFilterIDattributesontheRADIUS
server.Thisseparationgivesadministratorsmoreflexibilityinsegmentingtheirnetworksbeyond
theplatform’spolicyrolelimits.
When Policy Maptable Response is “Both”
HybridauthenticationmodeusesbothFilterIDattributesandtunnelattributes.Toenablehybrid
authenticationmode,usethesetpolicymaptablecommandandsettheresponseparameterto
both.Whenconfiguredtousebothsetsofattributes:
•IfboththeFilterIDandtunnelattributesarepresentintheRADIUSreply,
thenthepolicy
profilespecifiedbytheFilterIDisappliedtotheauthenticatinguser,andifVLAN
Note: Hybrid authentication is supported by modular switch devices, B-Series and C-Series
stackable fixed switches and the G3 device for Releases 6.3 and greater.