Supported Radius Attributes - ZyXEL Communications GS2210 Series User Manual

Intelligent layer 2 gbe switch
Hide thumbs Also See for GS2210 Series:
Table of Contents

Advertisement

The following table describes the VSAs supported on the Switch.
Table 95 Supported VSAs
FUNCTION
Ingress Bandwidth
Assignment
Egress Bandwidth
Assignment
Privilege Assignment
25.6.1.1 Tunnel Protocol Attribute
You can configure tunnel protocol attributes on the RADIUS server (refer to your RADIUS server
documentation) to assign a port on the Switch to a VLAN based on IEEE 802.1x authentication. The
port VLAN settings are fixed and untagged. This will also set the port's VID. The following table
describes the values you need to configure. Note that the bolded values in the table are fixed values
as defined in RFC 3580.
Table 96 Supported Tunnel Protocol Attribute
FUNCTION
VLAN Assignment

25.6.2 Supported RADIUS Attributes

Remote Authentication Dial-In User Service (RADIUS) attributes are data used to define specific
authentication elements in a user profile, which is stored on the RADIUS server. This appendix lists
the RADIUS attributes supported by the Switch.
Refer to RFC 2865 for more information about RADIUS attributes used for authentication.
This section lists the attributes used by authentication functions on the Switch. In cases where the
attribute has a specific format associated with it, the format is specified.
Chapter 25 AAA
ATTRIBUTE
Vendor-Id = 890
Vendor-Type = 1
ingress rate (Kbps in decimal format)
Vendor-data =
Vendor-Id = 890
Vendor-Type = 2
egress rate (Kbps in decimal format)
Vendor-data =
Vendor-ID = 890
Vendor-Type = 3
Vendor-Data = "shell:priv-lvl=N"
or
(CISCO)
Vendor-ID = 9
(CISCO-AVPAIR)
Vendor-Type = 1
Vendor-Data = "shell:priv-lvl=N"
where
is a privilege level (from 0 to 14).
N
Note: If you set the privilege level of a login account differently on the RADIUS server(s)
and the Switch, the user is assigned a privilege level from the database (RADIUS
or local) the Switch uses first for user authentication.
ATTRIBUTE
Tunnel-Type = VLAN(13)
Tunnel-Medium-Type = 802(6)
Tunnel-Private-Group-ID =
Note: You must also create a VLAN with the specified VID on the Switch.
GS2210 Series User's Guide
220
VLAN ID

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents