Configuring Dynamic Vlan Assignment With Port Authentication - Dell S4048T Configuration Manual

On system
Table of Contents

Advertisement

dot1x server-timeout seconds
The range is from 1 to 300.
The default is 30.
Example of Viewing Configured Server Timeouts
The example shows configuration information for a port for which the authenticator terminates the
authentication process for an unresponsive supplicant or server after 15 seconds.
The bold lines show the new supplicant and server timeouts.
Dell(conf-if-Te-1/1)#dot1x port-control force-authorized
Dell(conf-if-Te-1/1)#do show dot1x interface TenGigabitEthernet 1/1
802.1x information on Te 1/1:
-----------------------------
Dot1x Status:
Port Control:
Port Auth Status:
Re-Authentication:
Untagged VLAN id:
Guest VLAN:
Guest VLAN id:
Auth-Fail VLAN:
Auth-Fail VLAN id:
Auth-Fail Max-Attempts:
Tx Period:
Quiet Period:
ReAuth Max:
Supplicant Timeout:
Server Timeout:
Re-Auth Interval:
Max-EAP-Req:
Auth Type:
Auth PAE State:
Backend State:
Enter the tasks the user should do after finishing this task (optional).
Configuring Dynamic VLAN Assignment
with Port Authentication
Dell Networking OS supports dynamic VLAN assignment when using 802.1X.
The basis for VLAN assignment is RADIUS attribute 81, Tunnel-Private-Group-ID. Dynamic VLAN assignment
uses the standard dot1x procedure:
1
The host sends a dot1x packet to the Dell Networking system
2
The system forwards a RADIUS REQEST packet containing the host MAC address and ingress port
number
3
The RADIUS server authenticates the request and returns a RADIUS ACCEPT message with the VLAN
assignment using Tunnel-Private-Group-ID
Enable
FORCE_AUTHORIZED
UNAUTHORIZED
Disable
None
Disable
NONE
Disable
NONE
NONE
90 seconds
120 seconds
10
15 seconds
15 seconds
7200 seconds
10
SINGLE_HOST
Initialize
Initialize
802.1X
126

Advertisement

Table of Contents
loading

Table of Contents