Specifications
Configuring Authentication
April 15, 2011 Page 26 of 36
IftheauthenticationserverreturnsaninvalidpolicyorVLANtoaswitchforanauthenticating
supplicant,aninvalidactionofforward,drop,ordefaultpolicycanbeconfigured.
Procedure 13describessettingdynamicpolicyprofileassignmentandinvalidpolicyaction
configuration.
Configuring RADIUS
Youcanset,clear,anddisplayRADIUSconfigurationforbothau thenticationandaccounting.
Configuring the Authentication Server
Therearefouraspectstoconfiguringtheauthenticationserver:
• StateenablesordisablestheRADIUSclientforthisswitch.
• Establishmen tvaluesconfigureatimersettingthelengthoftimebeforeretries,aswellasthe
numberofretries,beforetheswitchdeterminestheauthenticationserverisdownand
attemptstoestablish
withthenextserverinitslist.
• ServeridentificationprovidesfortheconfigurationoftheserverIPaddressandindexvalue.
Theindexdeterminestheorderinwhichtheswitchwillattempttoestablishasessionwithan
authenticationserver.AftersettingtheindexandIPaddressyouareprompted
toentera
secretvalueforthisauthenticationserver.Anyauthenticationrequeststothisauthentication
servermustpresentthecorrectsecretvaluetogainauthentication.
•Therealmprovidesforconfigurationscopeforthisserver:managementaccess,network
access,orboth.
FirmwaresupportstheconfigurationofmultipleASs.Thelowestindexvalue
associatedwiththe
serverdeterminestheprimaryserver.Iftheprimary serverisdown,theoperationalserverwith
thenextlowestindexvalueisused. Iftheswitchfailstoestablishcontactwiththeauthentication
serverbeforeaconfiguredtimeout,theswitchwillretryfortheconfigurednumberoftimes.
Servers
canberestrictedtomanagementaccessornetworkaccessauthenticationbyconfiguring
therealmoption.
Procedure 13 Policy Profile Assignment and Invalid Action Configuration
Step Task Command(s)
1. Identify the profile index to be used in the
VID-to-policy mapping.
show policy profile all
2. Map the VLAN ID to the profile index. set policy maptable {vlan-list profile-index |
response {tunnel | policy | both}}
3. Display the current maptable configuration. show policy maptable.
4. Set the action to take when an invalid policy or
VLAN is received by the authenticating switch.
set policy invalid action {default-policy |
drop | forward}
Note: Dynamic policy profile assignment is supported on the Matrix E1 and modular
switch platforms.