Specifications

Configuring Authentication
April 15, 2011 Page 25 of 36
Configuring VLAN Authorization
VLANauthorizationallowsforthedynamicassignmentofuserstothesameVLAN.You
configureVLANauthorizationattributeswithinRADIUS.OntheswitchyouenableVLAN
authorizationbothgloballyandperport.VLANauthorizationisdisabledgloballybydefault.
VLANauthorizationisenabledperportbydefault.Youcanalsoset
theVLANegressformat
perport.VLANegressformatdefaultstountagged.VLANegressformatcanbesetasfollows:
noneNoegressmanipulationwillbemade.
taggedTheauthenticatingportwillbeaddedtothecurrenttaggedegressfortheVLANID
returned.
untaggedThe
authenticatingportwillbeaddedtothecurrentuntaggedegressforthe
VLANIDreturned.
dynamicEgressformattingwillbebaseduponinformationcontainedintheauthenticati on
response.
TheVLANauthorizationtablewillalwayslistanytunnelattribute’sVIDsthathavebeenreceived
forauthenticatedendsystems,butaVID
willnotactuallybeassignedunlessVLANauthorization
isenabledbothgloballyandontheauthenticatingport.DynamicVLANauthorizationoverrides
theportPVID.DynamicVLANauthorizationisnotreflectedintheshowportvlandisplay.The
VLANegresslistmaybestaticallyconfigured,enabledbaseduponthesetvlanauthorization
egresscommand,orhavedynamicegressenabledtoallowfullVLANmembershipand
connectivity.
Procedure 12describessettingVLANauthorizationconfiguration.
Setting Dynamic Policy Profile Assignment and Invalid Policy Action
Dynamicpolicyprofileassignmentisimplementedusingthepolicymappingtable.WhenVLAN
authorizationisenabled,authenticatedusersaredynamicallyassignedtothereceivedtunnel
attribute’sVID,unlesspreemptedbyapolicymaptableconfigurationentry.Dynamicpolicy
profileassignmentissupportedbymappingaVIDtoapolicyroleupon
receiptofaRADIUS
tunnelattribute.
Display MultiAuth authentication idle timeout values. show multiauth idle-timeout
Display MultiAuth authentication session timeout values. show multiauth session-timeout
Display MultiAuth authentication trap settings. show multiauth trap
Table 3 MultiAuth Authentication Traps Configuration (continued)
Task Command(s)
Procedure 12 VLAN Authorization Configuration
Step Task Command(s)
1. Enable or disable VLAN authorization both
globally and per port.
set vlanauthorization {enable | disable}
2. Reset VLAN authorization configuration to
default values for the specified port-list or for all.
clear valanauthorization {port-list | all}
3. Display VLAN authorization configuration
settings for the specified port-list or for all.
show vlanauthorization {port-list | all}