Specifications

Policy Overview
May 18, 2009 Page 6 of 32
UsethesetpolicymaptablecommandspecifyingasingleVLANIDorrangeofIDsandthepolicy
profileindextocreateapolicymaptableentry.
Applying Policy Using the RADIUS Response Attributes
Ifanauthenticationmethodthatrequirescommunicationwithanauthenticationserveris
configuredforauser,theRADIUS filterIDattributecanbeusedtodynamicallyassignapolicy
roletotheauthenticatinguser.SupportedRADIUSattributesaresenttotheswitchintheRADIUS
accessacceptmessage.TheRADIUSfilter
IDcanalsobeappliedinhybridauthenticationmode.
HybridauthenticationmodedetermineshowtheRADIUSfilterIDandthethreeRFC3580VLAN
tunnelattributes(VLANAuthorization),wheneitherorallareincludedintheRADIUS
accessacceptmessage,willbehandledbytheswitch.ThethreeVLANtunnel
attributesdefinethe
baseVLANIDtobeappliedtotheuser.Ineithercase,conflictresolutionbetweenRADIUS
attributesisprovidedbythemaptableresponsefeature.
PleaseseetheConfiguringUserAuthenticationfeatureguidelocatedat
http://secure.enterasys.com/support/manuals/foradiscussionofRADIUSconfiguration,the
RADIUSfilterID,andVLANauthorization.
Use
thepolicyoptionofthesetpolicymaptableresponsecommandtoconfiguretheswitchto
dynamicallyassignapolicyusingtheRADIUSfilterIDintheRADIUSresponsemessage.
Applying Policy Using Hybrid Authentication Mode
Enhanced Policy
Hybridauthenticationisanauthenticationcapabilitythatallowstheswitchtouseboththe
filterIDandtunnelattributesintheRADIUSresponsemessagetodeterminehowtotreatthe
authenticatinguser.
Hybridauthenticationisconfiguredbyspecifyingthebothoptioninthesetpolicymaptable
command.Thebothoption:
•Applies
theVLANtunnelattributesiftheyexistandthefilterIDattributedoesnot
•AppliesthefilterIDattributeifitexistsandtheVLANtunnelattributesdonot
Note: VLAN-to-Policy mapping is supported on the B3, C3, and G3 switches for firmware releases
6.3 and greater.
Note: VLAN-to-policy mapping to maptable response configuration behavior is as follows:
If the RADIUS response is set to policy, any VLAN-to-policy maptable configuration is ignored
for all platforms.
If the RADIUS response is set to tunnel, VLAN-to-policy mapping can occur on an N-Series
platform; VLAN-to-policy mapping will not occur on a SecureStack or standalone platform.
If the RADIUS response is set to both and both the filter-ID and tunnel attributes are present,
VLAN-to-policy mapping configuration is ignored. See the “When Policy Maptable Response is
Both” section of the Configuring User Authentication feature guide for exceptions to this
behavior.
Note: Hybrid authentication is an enhanced policy capability. For the B3, C3, and G3 platforms,
hybrid authentication is supported for Releases 6.3 and greater.