Specifications
Policy Overview
May 18, 2009 Page 6 of 32
UsethesetpolicymaptablecommandspecifyingasingleVLANIDorrangeofIDsandthepolicy
profile‐indextocreateapolicymaptableentry.
Applying Policy Using the RADIUS Response Attributes
Ifanauthenticationmethodthatrequirescommunicationwithanauthenticationserveris
configuredforauser,theRADIUS filter‐IDattributecanbeusedtodynamicallyassignapolicy
roletotheauthenticatinguser.SupportedRADIUSattributesaresenttotheswitchintheRADIUS
access‐acceptmessage.TheRADIUSfilter
‐IDcanalsobeappliedinhybridauthenticationmode.
HybridauthenticationmodedetermineshowtheRADIUSfilter‐IDandthethreeRFC3580VLAN
tunnelattributes(VLANAuthorization),wheneitherorallareincludedintheRADIUS
access‐acceptmessage,willbehandledbytheswitch.ThethreeVLANtunnel
attributesdefinethe
baseVLAN‐IDtobeappliedtotheuser.Ineithercase,conflictresolutionbetweenRADIUS
attributesisprovidedbythemaptableresponsefeature.
PleaseseetheConfiguringUserAuthenticationfeatureguidelocatedat
http://secure.enterasys.com/support/manuals/foradiscussionofRADIUSconfiguration,the
RADIUSfilter‐ID,andVLANauthorization.
Use
thepolicyoptionofthesetpolicymaptableresponsecommandtoconfiguretheswitchto
dynamicallyassignapolicyusingtheRADIUSfilter‐IDintheRADIUSresponsemessage.
Applying Policy Using Hybrid Authentication Mode
Enhanced Policy
Hybridauthenticationisanauthenticationcapabilitythatallowstheswitchtouseboththe
filter‐IDandtunnelattributesintheRADIUSresponsemessagetodeterminehowtotreatthe
authenticatinguser.
Hybridauthenticationisconfiguredbyspecifyingthebothoptioninthesetpolicymaptable
command.Thebothoption:
•Applies
theVLANtunnelattributesiftheyexistandthefilter‐IDattributedoesnot
•Appliesthefilter‐IDattributeifitexistsandtheVLANtunnelattributesdonot
Note: VLAN-to-Policy mapping is supported on the B3, C3, and G3 switches for firmware releases
6.3 and greater.
Note: VLAN-to-policy mapping to maptable response configuration behavior is as follows:
• If the RADIUS response is set to policy, any VLAN-to-policy maptable configuration is ignored
for all platforms.
• If the RADIUS response is set to tunnel, VLAN-to-policy mapping can occur on an N-Series
platform; VLAN-to-policy mapping will not occur on a SecureStack or standalone platform.
• If the RADIUS response is set to both and both the filter-ID and tunnel attributes are present,
VLAN-to-policy mapping configuration is ignored. See the “When Policy Maptable Response is
Both” section of the Configuring User Authentication feature guide for exceptions to this
behavior.
Note: Hybrid authentication is an enhanced policy capability. For the B3, C3, and G3 platforms,
hybrid authentication is supported for Releases 6.3 and greater.