Specifications
Configuring Authentication
April 15, 2011 Page 25 of 36
Configuring VLAN Authorization
VLANauthorizationallowsforthedynamicassignmentofuserstothesameVLAN.You
configureVLANauthorizationattributeswithinRADIUS.OntheswitchyouenableVLAN
authorizationbothgloballyandper‐port.VLANauthorizationisdisabledgloballybydefault.
VLANauthorizationisenabledperportbydefault.Youcanalsoset
theVLANegressformat
per‐port.VLANegressformatdefaultstoun‐tagged.VLANegressformatcanbesetasfollows:
• none–Noegressmanipulationwillbemade.
• tagged–TheauthenticatingportwillbeaddedtothecurrenttaggedegressfortheVLAN‐ID
returned.
• untagged–The
authenticatingportwillbeaddedtothecurrentuntaggedegressforthe
VLAN‐IDreturned.
• dynamic–Egressformattingwillbebaseduponinformationcontainedintheauthenticati on
response.
TheVLANauthorizationtablewillalwayslistanytunnelattribute’sVIDsthathavebeenreceived
forauthenticatedendsystems,butaVID
willnotactuallybeassignedunlessVLANauthorization
isenabledbothgloballyandontheauthenticatingport.DynamicVLANauthorizationoverrides
theportPVID.DynamicVLANauthorizationisnotreflectedintheshowportvlandisplay.The
VLANegresslistmaybestaticallyconfigured,enabledbaseduponthesetvlanauthorization
egresscommand,orhavedynamicegressenabledtoallowfullVLANmembershipand
connectivity.
Procedure 12describessettingVLANauthorizationconfiguration.
Setting Dynamic Policy Profile Assignment and Invalid Policy Action
Dynamicpolicyprofileassignmentisimplementedusingthepolicymappingtable.WhenVLAN
authorizationisenabled,authenticatedusersaredynamicallyassignedtothereceivedtunnel
attribute’sVID,unlesspreemptedbyapolicymap‐tableconfigurationentry.Dynamicpolicy
profileassignmentissupportedbymappingaVIDtoapolicyroleupon
receiptofaRADIUS
tunnelattribute.
Display MultiAuth authentication idle timeout values. show multiauth idle-timeout
Display MultiAuth authentication session timeout values. show multiauth session-timeout
Display MultiAuth authentication trap settings. show multiauth trap
Table 3 MultiAuth Authentication Traps Configuration (continued)
Task Command(s)
Procedure 12 VLAN Authorization Configuration
Step Task Command(s)
1. Enable or disable VLAN authorization both
globally and per port.
set vlanauthorization {enable | disable}
2. Reset VLAN authorization configuration to
default values for the specified port-list or for all.
clear valanauthorization {port-list | all}
3. Display VLAN authorization configuration
settings for the specified port-list or for all.
show vlanauthorization {port-list | all}