Specifications
Overview of Security Methods
SecureStack C3 Configuration Guide 21-3
returnsaRADIUSAccess‐AcceptmessagethatincludesaFilter‐IDmatchingapolicyprofilename
configuredontheswitch,theswitchthendynamicallyappliesthepolicyprofiletothephysical
porttheuser/deviceisauthenticatingon.
Filter-ID Attribute Formats
EnterasysNetworkssupportstwoFilter‐IDformats—“decorated”and“undecorated.”The
decoratedformathasthreeforms:
•Tospecifythepolicyprofiletoassigntotheauthenticatinguser(networkaccess
authentication):
Enterasys:version=1:policy=string
wherestringspecifiesthepolicyprofilename.Policyprofilenamesarecase‐sensitive.
•Tospecifyamanagementlevel(managementaccess
authentication):
Enterasys:version=1:mgmt=level
wherelevelindicatesthemanagementlevel,eitherro,rw,orsu.
•Tospecifybothmanagementlevelandpolicyprofile:
Enterasys:version=1:mgmt=level:policy=string
Theundecoratedformatissimplyastringthatspecif iesapolicyprofilename.Theundecorated
formatcannotbeusedformanagementaccessauthentication.
DecoratedFilter‐IDsareprocessed
firstbytheswitch.IfnodecoratedFilter‐IDsarefound,then
undecoratedFilter‐IDsareprocessed.IfmultipleFilter‐IDsarefoundthatcontainconflicting
values,aSyslogmessageisgenerated.