Authentication-Failure Actions; Supported Radius Attributes; Dynamic Vlan And Acl Assignments - Dell PowerConnect B-RX Configuration Manual

Bigiron rx series configuration guide v02.7.02
Hide thumbs Also See for PowerConnect B-RX:
Table of Contents

Advertisement

31
How multi-device port authentication works
traffic from this MAC address is encountered on a MAC-authentication-enabled interface, the
device sends the RADIUS server an Access-Request message with 0007e90feaa1 as both the
username and password. The format of the MAC address sent to the RADIUS server is configurable
through the CLI.
The request for authentication from the RADIUS server is successful only if the username and
password provided in the request matches an entry in the users database on the RADIUS server.
When this happens, the RADIUS server returns an Access-Accept message back to the device
device. When the RADIUS server returns an Access-Accept message for a MAC address, that MAC
address is considered authenticated, and traffic from the MAC address is forwarded normally by
the device device.

Authentication-failure actions

If the MAC address does not match the username and password of an entry in the users database
on the RADIUS server, then the RADIUS server returns an Access-Reject message. When this
happens, it is considered an authentication failure for the MAC address. When an authentication
failure occurs, the device can either drop traffic from the MAC address in hardware (the default), or
move the port on which the traffic was received to a restricted VLAN.
BigIron RX Series support multi-device port authentication on untagged ports only.

Supported RADIUS attributes

The device supports the following RADIUS attributes for multi-device port authentication:

Dynamic VLAN and ACL assignments

The multi-device port authentication feature supports dynamic VLAN assignment, where a port can
be placed in a VLAN based on the MAC address learned on that interface. When a MAC address is
successfully authenticated, the RADIUS server sends the device a RADIUS Access-Accept message
that allows the device to forward traffic from that MAC address. The RADIUS Access-Accept
message can also contain attributes set for the MAC address in its access profile on the RADIUS
server.
If one of the attributes in the Access-Accept message specifies a VLAN identifier, and this VLAN is
available on the BigIron RX device, the port is moved from its default VLAN to the specified VLAN.
To enable dynamic VLAN assignment for authenticated MAC addresses, you must add the following
attributes to the profile for the MAC address on the RADIUS server. Dynamic VLAN assignment on
multi-device port authentication-enabled interfaces is enabled by default.
928
Username (1) – RFC 2865
FilterId (11) – RFC 2865
Vendor-Specific Attributes (26) – RFC 2865
Tunnel-Type (64) – RFC 2868
Tunnel-Medium-Type (65) – RFC 2868
EAP Message (79) – RFC 2579
Tunnel-Private-Group-Id (81) – RFC 2868
BigIron RX Series Configuration Guide
53-1001810-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Brocade dcx-4sBrocade dcx

Table of Contents