Vsa Match Conditions And Actions For Ex Series Switches - Juniper JUNOS OS 10.3 - SOFTWARE Manual

For ex series ethernet switches
Hide thumbs Also See for JUNOS OS 10.3 - SOFTWARE:
Table of Contents

Advertisement

Complete Software Guide for Junos
Related
Documentation

VSA Match Conditions and Actions for EX Series Switches

Table 345: Match Conditions
Option
destination-mac mac-address
source-vlan source-vlan
2626
®
OS for EX Series Ethernet Switches, Release 10.3
user@switch# set fast-start 6
Configuring LLDP (J-Web Procedure) on page 2623
Example: Setting Up VoIP with 802.1X and LLDP-MED on an EX Series Switch on
page 2580
Configuring LLDP (CLI Procedure) on page 2622
Understanding 802.1X and LLDP and LLDP-MED on EX Series Switches on page 2540
EX Series switches support the configuration of RADIUS server attributes specific to
Juniper Networks. These attributes are known as vendor-specific attributes (VSAs). They
are configured on RADIUS servers and work in combination with 802.1X authentication.
Using VSAs, you can apply port firewall filter attributes as a subset of match conditions
and actions sent from the RADIUS server to the switch as a result of 802.1X authentication
success.
Each term in a VSA configured through the RADIUS server consists of match conditions
and an action. Match conditions are the values or fields that the packet must contain.
You can define single, multiple, or no match conditions. If no match conditions are
specified for the term, the packet is accepted by default. The action is the action that
the switch takes if a packet matches the match conditions for the specific term. Allowed
actions are accept a packet or discard a packet.
The following guidelines apply when you specify match conditions and actions for VSAs:
Both
match
and
action
statements are mandatory.
Any or all options (separated by commas) may be included in each
statement.
Fields separated by commas will be ANDed if they are of a different type. The same
types cannot be repeated.
For OR cases (for example, match
the 802.1X supplicant.
In order for the
forwarding-class
configured on the switch. If it is not configured on the switch, this option is ignored.
Table 345 on page 2626 describes the match conditions you can specify when configuring
a VSA using the
command on the RADIUS server. The string that defines a match
match
condition is called a match statement.
Description
Destination media access control (MAC) address of the packet.
Name of the source VLAN.
OR
10.1.1.0/24
11.1.1.0/24
option to be applied, the forwarding class must be
Copyright © 2010, Juniper Networks, Inc.
and
match
action
), apply multiple VSAs to

Advertisement

Table of Contents
loading

Table of Contents