84 - Configuration Pages
RocketLinx MP1204-XT User Guide
: 2000644 Rev. A
Security | Network | NAS
RADIUS-Assigned
VLAN Enabled
When
RADIUS-Assigned VLAN
is both globally enabled and enabled (checked) for a
given port, the MP1204-XT reacts to VLAN ID information carried in the RADIUS
Access-Accept packet transmitted by the RADIUS server when a supplicant is
successfully authenticated. If present and valid, the ports
Port VLAN ID
is changed
to this VLAN ID, the port is set to be a member of that VLAN ID, and the port is
forced into VLAN unaware mode. Once assigned, all traffic arriving on the port is
classified and switched on the RADIUS-assigned VLAN ID.
If (re-)authentication fails or the RADIUS Access-Accept packet no longer carries a
VLAN ID or its invalid, or the supplicant is otherwise no longer present on the
port, the ports VLAN ID is immediately reverted to the original VLAN ID (which
may be changed by the administrator in the meanwhile without affecting the
RADIUS-assigned).
This option is only available for single-client modes:
•
Port-based 802.1X
•
Single 802.1X
For troubleshooting VLAN assignments, use the
Monitor | VLANs | VLAN
Membership
and
VLAN Port
pages. These pages show which modules have
(temporarily) overridden the current Port VLAN configuration.
RADIUS attributes used in identifying a VLAN ID; RFC2868 and RFC3580 form
the basis for the attributes used in identifying a VLAN ID in an Access-Accept
packet. The following criteria are used:
•
The T
unnel-Medium-Type
,
Tunnel-Type
, and
Tunnel-Private-Group-ID
attributes
must all be present at least once in the Access-Accept packet.
•
The MP1204-XT looks for the first set of these attributes that have the same
Tag value and fulfill the following requirements (if Tag == 0 is used, the
Tunnel-Private-Group-ID
does not need to include a
Tag
):
•
Value of
Tunnel-Medium-Type
must be set to IEEE-802 (ordinal 6).
•
Value of
Tunnel-Type
must be set to VLAN (ordinal 13).
•
Value of
Tunnel-Private-Group-ID
must be a string of ASCII chars in the range
0 - 9, which is interpreted as a decimal string representing the VLAN ID.
Leading 0s are discarded. The final value must be in the range [1; 4095].
Item
Configuration | Security | Network | NAS (Continued)
Summary of Contents for RocketLinx MP1204-XT
Page 28: ...28 Installing the Hardware RocketLinx MP1204 XT User Guide 2000644 Rev A System Reset ...
Page 36: ...36 Web Interface Overview RocketLinx MP1204 XT User Guide 2000644 Rev A Ending a Session ...
Page 180: ...180 Configuration Pages RocketLinx MP1204 XT User Guide 2000644 Rev A Configuration DDMI ...
Page 414: ...414 Glossary RocketLinx MP1204 XT User Guide 2000644 Rev A Y ...