Specifications
Configuring VLAN Authorization (RFC 3580)
SecureStack B2 Configuration Guide 19-45
Configuring VLAN Authorization (RFC 3580)
Purpose
RFC3580TunnelAttributesprovideamechanismtocontainan802.1XauthenticatedoraMAC
authenticatedusertoaVLANregardlessofthePVID.Uptothreeuserscanbeconfiguredper
Gigabitport.
Pleaseseesection3‐31ofRFC3580fordetailsonconfiguringaRADIUSservertoreturn
the
desiredtunnelattributes.AsstatedinRFC3580,“...itmaybedesirabletoallowaporttobeplaced
intoaparticularVirtualLAN(VLAN),definedin[IEEE8021Q],basedontheresultofthe
authentication.”
TheRADIUSservertypicallyindicatesthedesiredVLANbyincludingtunnelattributeswithinits
Access‐Acceptparameters.However,theIEEE802.1XorMACauthenticatorcanalsobe
configuredtoinstructtheVLANtobeassignedtothesupplicantbyincludingtunnelattributes
withinAccess‐Requestparameters.
ThefollowingtunnelattributesareusedinVLANauthorizationassignment,:
•Tunnel‐Type‐VLAN(13)
•Tunnel‐Medium‐Type‐802
•Tunnel‐
Private‐Group‐ID‐VLANID
InordertoauthenticatemultipleRFC3580users,policymaptableresponsemustbesettotunnel
asdescribedinthissection.
Commands
show policy maptable response
Displaysthecurrentpolicymaptableresponsesetting.WhenVLANauthorizationisenabled(as
describedinthissection)andthepolicymaptableresponseistunnel,youcanusetheset
Notes: The B2 cannot simultaneously support Policy and RFC 3580 on the same port. If multiple
users are configured to use a port, and the B2 is then switched from "policy" mode to RFC-3580
"tunnel" mode, the total number of users supported to use a port will be reset to one.
A policy license, if applicable, is not required to run RFC3580.
For information about... Refer to page...
show policy maptable response 19-45
set policy maptable response 19-46
set vlanauthorization 19-47
set vlanauthorization egress 19-48
clear vlanauthorization 19-48
show vlanauthorization 19-49