Cisco Catalyst 2928 Software Configuration Manual page 192

Ios release 12.2(55)ez
Table of Contents

Advertisement

Understanding IEEE 802.1x Port-Based Authentication
When configured on the switch and the RADIUS server, IEEE 802.1x authentication with VLAN
assignment has these characteristics:
If no VLAN is supplied by the RADIUS server or if IEEE 802.1x authentication is disabled, the port
is configured in its access VLAN after successful authentication. Recall that an access VLAN is a
VLAN assigned to an access port. All packets sent from or received on this port belong to this
VLAN.
If IEEE 802.1x authentication is enabled but the VLAN information from the RADIUS server is not
valid, the port returns to the unauthorized state and remains in the configured access VLAN. This
prevents ports from appearing unexpectedly in an inappropriate VLAN because of a configuration
error. Configuration errors could include specifying a malformed VLAN ID, a nonexistent VLAN
ID, or an attempted assignment to a voice VLAN ID.
If IEEE 802.1x authentication is enabled and all information from the RADIUS server is valid, the
port is placed in the specified VLAN after authentication.
If the multiple-hosts mode is enabled on an IEEE 802.1x port, all hosts are placed in the same VLAN
(specified by the RADIUS server) as the first authenticated host.
If IEEE 802.1x authentication and port security are enabled on a port, the port is placed in the
RADIUS server-assigned VLAN.
If IEEE 802.1x authentication is disabled on the port, it is returned to the configured access VLAN.
When the port is in the force authorized, force unauthorized, unauthorized, or shutdown state, it is put
into the configured access VLAN.
If an IEEE 802.1x port is authenticated and put in the RADIUS server-assigned VLAN, any change to
the port access VLAN configuration does not take effect.
The IEEE 802.1x authentication with VLAN assignment feature is not supported on trunk ports, dynamic
ports, or with dynamic-access port assignment through a VLAN Membership Policy Server (VMPS).
To configure VLAN assignment you need to perform these tasks:
Enable AAA authorization by using the network keyword to allow interface configuration from the
RADIUS server.
Enable IEEE 802.1x authentication. (The VLAN assignment feature is automatically enabled when
you configure IEEE 802.1x authentication on an access port).
Assign vendor-specific tunnel attributes in the RADIUS server. The RADIUS server must return
these attributes to the switch:
Attribute [64] must contain the value VLAN (type 13). Attribute [65] must contain the value 802
(type 6). Attribute [81] specifies the VLAN name or VLAN ID assigned to the
IEEE 802.1x-authenticated user.
For examples of tunnel attributes, see the
Attributes" section on page
Catalyst 2928 Switch Software Configuration Guide
9-10
[64] Tunnel-Type = VLAN
[65] Tunnel-Medium-Type = 802
[81] Tunnel-Private-Group-ID = VLAN name or VLAN ID
8-29.
Chapter 9
Configuring IEEE 802.1x Port-Based Authentication
"Configuring the Switch to Use Vendor-Specific RADIUS
OL-23389-01

Advertisement

Table of Contents
loading

Table of Contents