Comtrol RocketLinx MP1204-XT User Manual page 84

Industrial poe managed switch 8 - gigabit copper ports 4 - gigabit sfp ports
Table of Contents

Advertisement

Security | Network | NAS
Item
RADIUS-Assigned
VLAN Enabled
84 - Configuration Pages
Configuration | Security | Network | NAS (Continued)
When RADIUS-Assigned VLAN is both globally enabled and enabled (checked) for a
given port, the MP1204-XT reacts to VLAN ID information carried in the RADIUS
Access-Accept packet transmitted by the RADIUS server when a supplicant is
successfully authenticated. If present and valid, the ports Port VLAN ID is changed
to this VLAN ID, the port is set to be a member of that VLAN ID, and the port is
forced into VLAN unaware mode. Once assigned, all traffic arriving on the port is
classified and switched on the RADIUS-assigned VLAN ID.
If (re-)authentication fails or the RADIUS Access-Accept packet no longer carries a
VLAN ID or its invalid, or the supplicant is otherwise no longer present on the
port, the ports VLAN ID is immediately reverted to the original VLAN ID (which
may be changed by the administrator in the meanwhile without affecting the
RADIUS-assigned).
This option is only available for single-client modes:
Port-based 802.1X
Single 802.1X
For troubleshooting VLAN assignments, use the Monitor | VLANs | VLAN
Membership and VLAN Port pages. These pages show which modules have
(temporarily) overridden the current Port VLAN configuration.
RADIUS attributes used in identifying a VLAN ID; RFC2868 and RFC3580 form
the basis for the attributes used in identifying a VLAN ID in an Access-Accept
packet. The following criteria are used:
The Tunnel-Medium-Type, Tunnel-Type, and Tunnel-Private-Group-ID attributes
must all be present at least once in the Access-Accept packet.
The MP1204-XT looks for the first set of these attributes that have the same
Tag value and fulfill the following requirements (if Tag == 0 is used, the
Tunnel-Private-Group-ID does not need to include a Tag):
Value of Tunnel-Medium-Type must be set to IEEE-802 (ordinal 6).
Value of Tunnel-Type must be set to VLAN (ordinal 13).
Value of Tunnel-Private-Group-ID must be a string of ASCII chars in the range
0 - 9, which is interpreted as a decimal string representing the VLAN ID.
Leading 0s are discarded. The final value must be in the range [1; 4095].
RocketLinx MP1204-XT User Guide: 2000644 Rev. A

Advertisement

Table of Contents
loading

Table of Contents