Specifications
Configuring VLAN Authorization (RFC 3580)
21-42 Security Configuration
Configuring VLAN Authorization (RFC 3580)
Purpose
Pleaseseesection3‐31ofRFC3580fordetailsonconfiguringaRADIUSservertoreturnthe
desiredtunnelattributes.FromRFC3580,“...itmaybedesirabletoallowaporttobeplacedintoa
particularVirtualLAN(VLAN),definedin[IEEE8021Q],based ontheresultofthe
authentication.”
TheRADIUSservertypicallyindicatesthedesiredVLANbyinclud ingtunnelattributeswithin
theAccess‐Accept.However,theIEEE802.1XAuthenticatormayalsoprovideahintastothe
VLANtobeassignedtotheSupplicantbyincludingTunnelattributeswithintheAccess‐Request.
ForuseinVLANassignment,the
followingtunnelattributesareused:
•Tunnel‐Type=VLAN(13)
•Tunnel‐Medium‐Type=802
•Tunnel‐Private‐Group‐ID=VLANID
Commands
ThecommandsusedtoconfigureRADIUStunnelattributesarelistedbelow.
For information about... Refer to page...
set vlanauthorization 21-43
set vlanauthorization egress 21-43
clear vlanauthorization 21-44
show vlanauthorization 21-45