Specifications
Authentication Overview
April 15, 2011 Page 13 of 36
authorizationisenabledgloballyandontheauthenticatinguser’sport,theVLANspecifiedby
thetunnelattributesisappliedtotheauthenticatinguser.
IfVLANauthorizationisnotenabled,theVLANspecifiedbythepolicyprofileisapplied.See
“RFC3580”onpage 10forinformationaboutVLANauthorization.
•Ifthe
Filter‐IDattribut esarepresentbutthetunnelattributesarenotpresent,thepolicy
profilespecifiedbytheFilter‐IDisapplied,alongwiththeVLANspecifiedbythepolicy
profile.
•IfthetunnelattributesarepresentbuttheFilter‐IDattributesarenotpresent,andifVLAN
authorizationisenabled
globallyandontheauthenticatinguser’sport,thentheswitchwill
checktheVLAN‐to‐policymappingtable(configuredwiththesetpolicymaptable
command):
–IfanentrymappingthereceivedVLANIDtoapolicyprofileisfound,thenthatpolicy
profile,alongwiththeVLANspecifiedbythepolicy
profile,willbeappliedtothe
authenticatinguser.
–Ifnomatchingmappingtableentryisfound,theVLANspecifiedbythetunnelattributes
willbeappliedtotheauthenticatinguser.
–IftheVLAN‐to‐policymappingtableisinvalid,thenthe
etsysPolicyRFC3580MapInvalidMappingMIBisincrementedandtheVLANspecifiedby
thetunnel
attributeswillbeappliedtotheauthenticatinguser.
IfVLANauthorizationisnotenabled,thetunnelattributesareignored.
When Policy Maptable Response is “Profile”
WhentheswitchisconfiguredtouseonlyFilter‐IDattributes,bysettingthesetpolicymaptable
commandresponseparametertopolicy:
•IftheFilter‐IDattributesarepresent,thespecifiedpolicyprofilewillbeappliedtothe
authenticatinguser.IfnoFilter‐IDattributesarepresent,thedefaultpolicy(if
itexists)willbe
applied.
•Ifthetunnelattributesarepresent,theyareignored.NoVLAN‐to‐policymappingwilloccur.
When Policy Maptable Response is “Tunnel”
Whentheswitchisconfiguredtouseonlytunnelattributes,bysettingthesetpolicymaptable
commandresponseparametertotunnel,andifVLANauthorizationisenabledbothgloballyand
ontheauthenticatinguser’sport:
•Ifthetunnelattributesarepresent,the sp ecifiedVLANwillbeappliedtotheauthenticating
user.
VLAN‐to‐policymappingcanoccuronamodularswitchplatform;VLAN‐to‐policy
mappingwillnotoccuronastackablefixedswitchorstandalonefixedswitchplatform.
•Ifthetunnelattributesarenotpresent,thedefaultpolicyVLANwillbeapplied;ifthedefault
policyVLANisnotconfigured,the
portVLANwillbeapplied.
•IftheFilter‐IDattributesarepresent,theyareignored.
IfVLANauthorizationisnotenabled,theuserwillbeallowedontotheportwiththedefault
policy,ifitexists.Ifnodefaultpolicyexists,theportVLANwillbeapplied.