Campus And Isp Modes; Interoperability Requirements; Vsa Definitions For Web-Based And 802.1X Network Login - Extreme Networks Summit 300-48 Software User's Manual

Extreme summit 300-48: software user guide
Hide thumbs Also See for Summit 300-48:
Table of Contents

Advertisement

Campus and ISP Modes

Network login supports two modes of operation, Campus and ISP. Campus mode is intended for
mobile users who tend to move from one port to another and connect at various locations in the
network. ISP mode is meant for users who connect through the same port and VLAN each time (the
switch functions as an ISP).
In campus mode, the clients are placed into a permanent VLAN following authentication with access to
network resources. For wired ports, the port is moved from the temporary to the permanent VLAN.
In ISP mode, the port and VLAN remain constant. Before the supplicant is authenticated, the port is in
an unauthenticated state. After authentication, the port forwards packets.
User Accounts
You can create two types of user accounts for authenticating network login users: netlogin-only enabled
and netlogin-only disabled. A netlogin-only disabled user can log in using network login and can also
access the switch using Telnet, SSH, or HTTP. A netlogin-only enabled user can only log in using
network login and cannot access the switch using the same login.
Add the following line to the RADIUS server dictionary file for netlogin-only disabled users:
Extreme:Extreme-Netlogin-Only = Disabled
Add the following line to the RADIUS server dictionary file for netlogin-only enabled users:
Extreme:Extreme-Netlogin-Only = Enabled
Table 45 contains the Vendor Specific Attribute (VSA) definitions for web-based network login. The
Extreme Network Vendor ID is 1916.
Table 45: VSA Definitions for Web-based and 802.1x Network Login
VSA
Extreme-Netlogin-VLAN 203
Extreme-Netlogin-URL
Extreme-Netlogin-URL-
Desc
Extreme-Netlogin-Only

Interoperability Requirements

For network login to operate, the user (supplicant) software and the authentication server must support
common authentication methods. Not all combinations provide the appropriate functionality.
Summit 300-48 Switch Software User Guide
Attribute
Value
Type
Sent-in
String
Access-Accept
204
String
Access-Accept
205
String
Access-Accept
206
Integer
Access-Accept
Description
Name of destination VLAN after successful
authentication (must already exist on switch).
Destination web page after successful
authentication.
Text description of network login URL attribute.
Indication of whether the user can authenticate
using other means, such as telnet, console,
SSH, or Vista. A value of "1" (enabled)
indicates that the user can only authenticate
via network login. A value of zero (disabled)
indicates that the user can also authenticate
via other methods.
Network Login
99

Advertisement

Table of Contents
loading

Table of Contents