Configuring VLAN Authorization (RFC 3580)
Purpose
RFC 3580 Tunnel Attributes provide a mechanism to contain an 802.1X authenticated or a MAC
authenticated user to a VLAN regardless of the PVID. Up to six users can be configured per
Gigabit port.
Please see section 3‐31 of RFC 3580 for details on configuring a RADIUS server to return the
desired tunnel attributes. As stated in RFC 3580, "... it may be desirable to allow a port to be placed
into a particular Virtual LAN (VLAN), defined in [IEEE8021Q], based on the result of the
authentication."
The RADIUS server typically indicates the desired VLAN by including tunnel attributes within its
Access‐Accept parameters. However, the IEEE 802.1X or MAC authenticator can also be
configured to instruct the VLAN to be assigned to the supplicant by including tunnel attributes
within Access‐Request parameters.
The following tunnel attributes are used in VLAN authorization assignment, :
•
Tunnel‐Type ‐ VLAN (13)
•
Tunnel‐Medium‐Type ‐ 802
•
Tunnel‐Private‐Group‐ID ‐ VLANID
In order to authenticate multiple RFC 3580 users, policy maptable response must be set to tunnel
as described in this section.
Commands
For information about...
show policy maptable response
set policy maptable response
set vlanauthorization
set vlanauthorization egress
clear vlanauthorization
show vlanauthorization
show policy maptable response
Displays the current policy maptable response setting. When VLAN authorization is enabled (as
described in this section) and the policy maptable response is tunnel, you can use the set
Notes: The C2 cannot simultaneously support Policy and RFC 3580 on the same port. If multiple
users are configured to use a port, and the C2 is then switched from "policy" mode to RFC-3580
"tunnel" mode, the total number of users supported to use a port will be reset to one.
A policy license, if applicable, is not required to run RFC3580.
Configuring VLAN Authorization (RFC 3580)
Refer to page...
23-45
23-46
23-47
23-48
23-48
23-49
SecureStack C2 Configuration Guide 23-45
Need help?
Do you have a question about the SecureStack C2 C2G170-24 and is the answer not in the manual?