Specifications
Authentication Overview
April 15, 2011 Page 12 of 36
•AproblemwithmovinganendsystemtoanewVLANisthattheendsystemmustbeissued
anIPaddressonthenewVLAN’ssubnettowhichithasbecomeamember.Iftheendsystem
doesnotyethaveanIPaddress,thisisnotusuallyaproblem.
However,iftheendsystemhas
anIPaddress,theleaseoftheaddressmusttimeoutbeforeitattemptstoobtainanew
address,whichmaytakesometime.TheIPaddressassignmentprocess,implementedby
DHCP,andtheauthenticationprocessarenotconjoinedontheendsystem.Therefore,
this
leadstoendsystemspossessinganinvalidIPaddressafterdynamicVLANAu thorizationand
lostIPconnectivityuntilitscurrentIPaddresstimesout.Furthermore,whenanewIPaddress
iseventuallyassignedtotheendsystem,IPconnectivityisdisruptedforallapplicationson
theendsystem.
Policy Maptable Response
Thepolicymaptableresponse,orconflictresolution,featureallowsyoutodefinehowthesystem
shouldhandleallowinganauthenticateduserontoaportbasedonthecontentsoftheRADIUS
Acceptmessagereply.Therearethreepossibleresponsesettings:tunnelmode,policymode,or
bothtunnelandpolicy,alsoknown
ashybridauthenticationmode.
Whenthemaptableresponseissettotunnelmode,thesystemwillusethetunnelattributesinthe
RADIUSreplytoapplyaVLANtotheauthenticatinguserandwillignoreanyFilter‐IDattributes
intheRADIUSreply.Whentunnelmodeisconfigured,VLAN‐to‐policy
mappingcanoccurif
configuredonamodularswitchplatform.VLAN‐to‐policymappingwillnotoccurintunnel
modeonastackablefixedswitchorstandalonefixedswitchplatform.
Whenthemaptableresponseissettopolicymode,thesystemwillusetheFilter‐IDattributesin
theRADIUS
replytoapplyapolicytotheauthenticatinguserandwillignoreanytunnel
attributesintheRADIUS reply.Whenpolicymodeisconfigured,noVLAN‐to‐policymapping
willoccur.
Whenthemaptableresponseissettoboth,orhybridauthenticationmode,bothFilter‐ID
attributes(dynamicpolicyassignment)and
tunnelattributes(dynamicVLANassignment)sentin
RADIUSAcceptmessagerepliesareusedtodeterminehowtheswitchshouldhandle
authenticatingusers.Whenhybridauthenticationmodeisconfigured,VLAN‐to‐policymapping
canoccur,asdescribedbelowinWhenPolicyMaptableResponseis“Both”.
Usinghybridauthenticationmodeeliminatesthe
dependencyonhavingtoassignVLANs
throughpolicyroles—VLANscanbeassignedbymeansofthetunnelattribu teswhilepolicy
rolescanbeassignedbymeansoftheFilter‐IDattributes.Alternatively,onmodularswitch
platforms,VLAN‐to‐policymappingcanbeusedtomappoliciestousersusing
theVLAN
specifiedbythetunnelattributes,withouthavingtoconfigureFilter‐IDattributesontheRADIUS
server.Thisseparationgivesadministratorsmoreflexibilityinsegmentingtheirnetworksbeyond
theplatform’spolicyrolelimits.
When Policy Maptable Response is “Both”
HybridauthenticationmodeusesbothFilter‐IDattributesandtunnelattributes.Toenablehybrid
authenticationmode,usethesetpolicymaptablecommandandsettheresponseparameterto
both.Whenconfiguredtousebothsetsofattributes:
•IfboththeFilter‐IDandtunnelattributesarepresentintheRADIUSreply,
thenthepolicy
profilespecifiedbytheFilter‐IDisappliedtotheauthenticatinguser,andifVLAN
Note: Hybrid authentication is supported by modular switch devices, B-Series and C-Series
stackable fixed switches and the G3 device for Releases 6.3 and greater.