Juniper JUNOS OS 10.3 - SOFTWARE Manual page 2714

For ex series ethernet switches
Hide thumbs Also See for JUNOS OS 10.3 - SOFTWARE:
Table of Contents

Advertisement

Complete Software Guide for Junos
Related
Documentation
Filtering 802.1X Supplicants Using RADIUS Server Attributes
2618
®
OS for EX Series Ethernet Switches, Release 10.3
User-Name = "000347e1bab9"
NAS-Port = 67
Acct-Status-Type = Stop
Acct-Session-Id = "8O2.1x811912"
Acct-Input-Octets = 17454
Acct-Output-Octets = 4245
Acct-Session-Time = 1221041249
Acct-Input-Packets = 72
Acct-Output-Packets = 53
Acct-Terminate-Cause = Lost-Carrier
Acct-Input-Gigawords = 0
Acct-Output-Gigawords = 0
Called-Station-Id = "00-19-e2-50-52-60"
Calling-Station-Id = "00-03-47-e1-ba-b9"
Event-Timestamp = "Sep 10 2008 16:52:39 PDT"
NAS-Identifier = "esp48t-1b-01"
NAS-Port-Type = Virtual
User-Name = "000347e1bab9"
NAS-Port = 67
Acct-Status-Type = Start
Acct-Session-Id = "8O2.1x811219"
Called-Station-Id = "00-19-e2-50-52-60"
Calling-Station-Id = "00-03-47-e1-ba-b9"
Event-Timestamp = "Sep 10 2008 18:58:52 PDT"
NAS-Identifier = "esp48t-1b-01"
NAS-Port-Type = Virtual
Example: Connecting a RADIUS Server for 802.1X to an EX Series Switch on page 2545
Understanding 802.1X and RADIUS Accounting on EX Series Switches on page 2539
There are two ways to configure the RADIUS server with port firewall filters:
Include a match statement and corresponding action in the
attribute. The
Juniper-Firewall-Filter
the Juniper dictionary on the RADIUS server. Use this attribute to configure simple filter
conditions for authenticated users. Nothing needs to be configured on the switch; all
of the configuration is on the RADIUS server.
Apply a local firewall filter to users authenticated through the RADIUS server. Use this
method for more complex filters. The firewall filter must be configured on each switch.
This example describes using FreeRADIUS software to configure VSAs. For specifics on
configuring your server, consult the AAA documentation that was included with your
server.
This topic includes the following tasks:
Configuring Match Statements on the RADIUS Server on page 2619
1.
Applying a Port Firewall Filter from the RADIUS Server on page 2621
2.
Juniper-Firewall-Filter
attribute is a vendor-specific attribute (VSA) in
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

Table of Contents