
DGS-3130 Series Layer 3 Stackable Managed Switch Web UI Reference Guide
474
Appendix D - RADIUS Attributes Assignment
The RADIUS Attributes Assignment on the Switch is used in the following modules: Console, Telnet, SSH, Web,
802.1X, MAC-based Access Control, and WAC.
The description that follows explains the following RADIUS Attributes Assignment types:
•
Privilege Level
•
Ingress/Egress Bandwidth
•
802.1p Default Priority
•
VLAN
•
ACL
To assign the
Privilege Level
by the RADIUS server, the proper parameters should be configured on the RADIUS
server. The table below shows the parameters for the bandwidth.
The parameters of the Vendor-Specific attributes are:
Vendor-Specific
Attribute
Description
Value
Usage
Vendor-ID
Defines the vendor.
171
(DLINK)
Required
Vendor-Type
Defines the attribute.
1
Required
Attribute-Specific Field
Used to assign the privilege level of the user to operate
the Switch.
Range (1-
15)
Required
If the user has configured the privilege level attribute of the RADIUS server (for example, level 15) and the Console,
Telnet, SSH, and Web authentication is successful, the device will assign the privilege level (according to the RADIUS
server) to this access user. However, if the user does not configure the privilege level attribute and authenticates
successfully, the device will not assign any privilege level to the access user. If the privilege level is configured less
than the minimum supported value or greater than the maximum supported value, the privilege level will be ignored.
To assign the
Ingress/Egress Bandwidth
by the RADIUS server, the proper parameters should be configured on the
RADIUS Server. The table below shows the parameters for bandwidth.
The parameters of the Vendor-Specific attributes are:
Vendor-Specific Attribute Description
Value
Usage
Vendor-ID
Defines the vendor.
171 (DLINK)
Required
Vendor-Type
Defines the attribute.
2 (for ingress bandwidth)
3 (for egress bandwidth)
Required
Attribute-Specific Field
Used to assign the bandwidth of a port.
Unit (Kbits)
Required
If the user has configured the bandwidth attribute of the RADIUS server (for example, ingress bandwidth 1000Kbps)
and 802.1X authentication is successful, the device will assign the bandwidth (according to the RADIUS server) to the
port. However, if the user does not configure the bandwidth attribute and authenticates successfully, the device will
not assign any bandwidth to the port. If the bandwidth attribute is configured on the RADIUS server with a value of “0”,
the effective bandwidth will be set “no_limited”, and if the bandwidth is configured less than “0” or greater than
maximum supported value, the bandwidth will be ignored.
Summary of Contents for DGS-3130 Series
Page 1: ......