Understanding 802.1X And Vsas On J-Ex Series Switches - Dell PowerConnect J-EX4200-24T Software Manual

J series; j-ex series
Table of Contents

Advertisement

Dell PowerConnect J-Series Ethernet Switch Complete Software Guide for Junos OS

Understanding 802.1X and VSAs on J-EX Series Switches

Related
Documentation
2266
J-EX Series Switches support the configuration of RADIUS server attributes specific to
Juniper Networks. These attributes are known as vendor-specific attributes (VSAs) and
are described in RFC 2138, Remote Authentication Dial In User Service (RADIUS). Through
VSAs, you can configure port-filtering attributes on the RADIUS server. VSAs are clear
text fields sent from the RADIUS server to the switch as a result of the 802.1X
authentication success or failure. The 802.1X authentication prevents unauthorized user
access by blocking a supplicant at the port until the supplicant is authenticated by the
RADIUS server. The VSA attributes are interpreted by the switch during authentication,
and the switch takes appropriate actions. Implementing port-filtering attributes with
802.1X authentication on the RADIUS server provides a central location for controlling
LAN access for supplicants.
These port-filtering attributes specific to Juniper Networks are encapsulated in a RADIUS
server VSA with the vendor ID set to the Juniper Networks ID number, 2636.
As well as configuring port-filtering attributes through VSAs, you can apply a port firewall
filter that has already been configured on the switch directly to the RADIUS server. Like
port-filtering attributes, the filter is applied during the 802.1X authentication process,
and its actions are applied at the switch port. Adding a port firewall filter to a RADIUS
server eliminates the need to add the filter to multiple ports and switches. For more
information, see "Example: Applying a Firewall Filter to 802.1X-Authenticated Supplicants
Using RADIUS Server Attributes on a J-EX Series Switch" on page 2296.
VSAs are only supported for 802.1X single-supplicant configurations and
multiple-supplicant configurations.
Understanding Authentication onJ-EX Series Switches on page 2248
Example: Setting Up 802.1X for Single Supplicant or Multiple Supplicant Configurations
on a J-EX Series Switch on page 2290
Filtering 802.1X Supplicants Using RADIUS Server Attributes on page 2340
Configuring Firewall Filters (CLI Procedure) on page 2779
VSA Match Conditions and Actions for J-EX Series Switches on page 2348

Advertisement

Table of Contents
loading

Table of Contents