Enterasys D-Series Specifications Page 509

  • Download
  • Add to my manuals
  • Print
  • Page
    / 540
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 508
set vlanauthorization
Enterasys D-Series CLI Reference 17-47
Whenausersuccessfullyauthenticatestothenetwork,theRADIUSserverreturnsanAccess
Acceptframe.Thisframecanhavemanyattributes,twoofwhichareaFilterID(whichishow
policyassignmentisachieved)andRFC3580VLANassignment.
Ifaswitchisintunnelmode:
•TheFID(FilterID)
isalwaysignored,butDefaultpolicyrulesstillapply.
•TheVLANattributeisusedifpresent,andifVLANauthorization isenabled.Seeset
vlanauthorizationonpage 1747.
Ifaswitchisinpolicymode:
•IftheAccessAcceptframehastheFIDattributeonly,thentheFIDisused.
•If
theAccessAcceptframehastheVLANattributeonly,thenitisusedprovidedthatVLAN
authorizationisenabled.Seesetvlanauthorizationonpage 1747.
•Ifbothattributesarereturned,usetheFIDonly.
Examples
Thisexampleshowshowtosetthepolicymaptableresponsetotunnel:
D2(rw)-> set policy maptable response tunnel
set vlanauthorization
EnableordisabletheuseoftheRADIUSVLANtunnelattributetoputaportintoaparticular
VLANbasedontheresultofauthentication.
Syntax
set vlanauthorization {enable | disable} [port-string]
Parameters
Defaults
VLANauthenticationisdisabledbydefault.
Mode
Switchcommand,readwrite.
Examples
ThisexampleshowshowtoenableVLANauthenticationforallGigabitEthernetports:
D2(rw)-> set vlanauthorization enable ge.*.*
ThisexampleshowshowtodisableVLANauthenticationforallGigabitEthernetportsonswitch
unit/module 3:
D2(rw)-> set vlanauthorization disable ge.3.*
enable|disable Enablesordisablesvlanauthorization/tunnelattributes.
portstring (Optional)SpecifieswhichportstoenableordisabletheuseofVLAN
tunnelattributes/authorization.Foradetaileddescriptionofpossibleport
stringvalues,refertoPortStringSyntaxUsedintheCLIonpage 61.
Page view 508
1 2 ... 504 505 506 507 508 509 510 511 512 513 514 ... 539 540

Comments to this Manuals

No comments