Alcatel-Lucent OmniSwitch AOS Release 7 Manual page 585

Network configuration guide
Hide thumbs Also See for OmniSwitch AOS Release 7:
Table of Contents

Advertisement

Vendor-Specific Attributes for RADIUS
The Alcatel-Lucent RADIUS client supports attribute 26, which includes a vendor ID and some addi-
tional sub-attributes called subtypes. The vendor ID and the subtypes collectively are called Vendor
Specific Attributes (VSAs). Alcatel-Lucent, through partnering arrangements, has included these VSAs in
some vendors' RADIUS server configurations.
The attribute subtypes are defined in the dictionary file of the server. If you are using single authority
mode, the first VSA subtype, Alcatel-Lucent-Auth-Vlan, must be defined on the server for each authenti-
cated VLAN. Alcatel-Lucent's vendor ID is 800 (SMI Network Management Private Enterprise Code).
The following are VSAs for RADIUS servers:
Num. RADIUS VSA
1 Alcatel-Lucent-Auth-Group
2 Alcatel-Lucent-Slot-Port
3 Alcatel-Lucent-Time-of-Day
4 Alcatel-Lucent-Client-IP-
Addr
5 Alcatel-Lucent-Group-Desc
6 Alcatel-Lucent-Port-Desc
8 Alcatel-Lucent-Auth-Group-
Protocol
9 Alcatel-Lucent-Asa-Access
39 Alcatel-Lucent-Acce-Priv-F-
R1
40 Alcatel-Lucent-Acce-Priv-F-
R2
41 Alcatel-Lucent-Acce-Priv-F-
W1
42 Alcatel-Lucent-Acce-Priv-F-
W2
The Alcatel-Lucent-Auth-Group attribute is used for Ethernet II only. If a different protocol, or more than
one protocol is required, use the Alcatel-Lucent-Auth-Group-Protocol attribute instead. For example:
Alcatel-Lucent-Auth-Group-Protocol 23: IP_E2 IP_SNAP
Alcatel-Lucent-Auth-Group-Protocol 24: IPX_E2
In this example, authenticated users on VLAN 23 can use Ethernet II or SNAP encapsulation.
Authenticated users on VLAN 24 can use IPX with Ethernet II.
OmniSwitch AOS Release 7 Network Configuration Guide
Type
Description
integer
The authenticated VLAN number. The only protocol
associated with this attribute is Ethernet II. If other
protocols are required, use the protocol attribute
instead.
string
Slot(s)/port(s) valid for the user.
string
The time of day valid for the user to authenticate.
address
The IP address used for Telnet only.
string
Description of the authenticated VLAN.
string
Description of the port.
string
The protocol associated with the VLAN. Must be
configured for access to other protocols. Values
include: IP_E2, IP_SNAP, IPX_E2, IPX_NOV,
IPX_LLC, IPX_SNAP.
string
Specifies that the user has access to the switch. The
only valid value is all.
hex.
Configures functional read privileges for the user.
hex.
Configures functional read privileges for the user.
hex.
Configures functional write privileges for the user.
hex.
Configures functional write privileges for the user.
March 2011
page 239

Advertisement

Table of Contents
loading

This manual is also suitable for:

Omniswitch aos 7

Table of Contents