Specifications

Authentication Overview
April 15, 2011 Page 13 of 36
authorizationisenabledgloballyandontheauthenticatingusersport,theVLANspecifiedby
thetunnelattributesisappliedtotheauthenticatinguser.
IfVLANauthorizationisnotenabled,theVLANspecifiedbythepolicyprofileisapplied.See
RFC3580onpage 10forinformationaboutVLANauthorization.
•Ifthe
FilterIDattribut esarepresentbutthetunnelattributesarenotpresent,thepolicy
profilespecifiedbytheFilterIDisapplied,alongwiththeVLANspecifiedbythepolicy
profile.
•IfthetunnelattributesarepresentbuttheFilterIDattributesarenotpresent,andifVLAN
authorizationisenabled
globallyandontheauthenticatingusersport,thentheswitchwill
checktheVLANtopolicymappingtable(configuredwiththesetpolicymaptable
command):
–IfanentrymappingthereceivedVLANIDtoapolicyprofileisfound,thenthatpolicy
profile,alongwiththeVLANspecifiedbythepolicy
profile,willbeappliedtothe
authenticatinguser.
–Ifnomatchingmappingtableentryisfound,theVLANspecifiedbythetunnelattributes
willbeappliedtotheauthenticatinguser.
–IftheVLANtopolicymappingtableisinvalid,thenthe
etsysPolicyRFC3580MapInvalidMappingMIBisincrementedandtheVLANspecifiedby
thetunnel
attributeswillbeappliedtotheauthenticatinguser.
IfVLANauthorizationisnotenabled,thetunnelattributesareignored.
When Policy Maptable Response is “Profile”
WhentheswitchisconfiguredtouseonlyFilterIDattributes,bysettingthesetpolicymaptable
commandresponseparametertopolicy:
•IftheFilterIDattributesarepresent,thespecifiedpolicyprofilewillbeappliedtothe
authenticatinguser.IfnoFilterIDattributesarepresent,thedefaultpolicy(if
itexists)willbe
applied.
•Ifthetunnelattributesarepresent,theyareignored.NoVLANtopolicymappingwilloccur.
When Policy Maptable Response is “Tunnel”
Whentheswitchisconfiguredtouseonlytunnelattributes,bysettingthesetpolicymaptable
commandresponseparametertotunnel,andifVLANauthorizationisenabledbothgloballyand
ontheauthenticatingusersport:
•Ifthetunnelattributesarepresent,the sp ecifiedVLANwillbeappliedtotheauthenticating
user.
VLANtopolicymappingcanoccuronamodularswitchplatform;VLANtopolicy
mappingwillnotoccuronastackablefixedswitchorstandalonefixedswitchplatform.
•Ifthetunnelattributesarenotpresent,thedefaultpolicyVLANwillbeapplied;ifthedefault
policyVLANisnotconfigured,the
portVLANwillbeapplied.
•IftheFilterIDattributesarepresent,theyareignored.
IfVLANauthorizationisnotenabled,theuserwillbeallowedontotheportwiththedefault
policy,ifitexists.Ifnodefaultpolicyexists,theportVLANwillbeapplied.