DWS-3160 Series Gigabit Ethernet Unified Switch CLI Reference Guide
968
If the user has configured the VLAN attribute of the RADIUS server (for example, VID 3) and the
802.1X, or MAC-based Access Control authentication is successful, the port will be added to VLAN
3. However, if the user does not configure the VLAN attribute and authenticates successfully, the
port will be kept in its original VLAN. If the VLAN attribute configured on the RADIUS server does
not exist, the port will not be assigned to the requested VLAN.
To assign
ACL by RADIUS Server
, the proper parameters should be configured on the RADIUS
Server. The table below shows the parameters for an ACL. The RADIUS ACL assignment is only
used in MAC-based Access Control.
The parameters of the Vendor-Specific Attribute are:
RADIUS Tunnel
Attribute
Description
Value
Usage
Vendor-ID
Defines the vendor.
171 (DLINK)
Required
Vendor-Type
Defines the attribute.
12 (for ACL profile)
13 (for ACL rule)
Required
Attribute-Specific
Field
Used to assign the ACL
profile or rule.
ACL Command
For example:
ACL profile: create access_profile
profile_id 6 profile_name 1 ethernet vlan
0xFFF;
ACL rule: config access_profile
profile_id 6 add access_id auto_assign
ethernet vlan_id 1 port all deny;
Required
If the user has configured the ACL attribute of the RADIUS server (for example, ACL profile:
create access_profile profile_id 6 profile_name 1 ethernet
; ACL rule:
config access_profile
profile_id 6 add access_id auto_assign ethernet
), and the 802.1X or MAC-based Access
Control or WAC authentication is successful, the device will assign the ACL profiles and rules
according to the RADIUS server. For more information about the ACL module, please refer to the
‘Access Control List (ACL) Command List’ chapter.
Since an AP configuration is determined by its physical MAC address, the administrator adds a
RADIUS entry for each AP with the User-Name attribute set to the MAC address. The following
table indicates the attributes that are configured in the RADIUS server entry. The vendor specific
attributes are added using the D-Link vendor ID (171).
AP RADIUS Attributes:
Attribute
Description
Range
Usage
Default
User-Name (1)
Ethernet Address of
the AP.
Valid Ethernet MAC
Address.
Required
None
User-Password (2)
A fixed password
used to lookup an AP
8-63 characters,
default
Required
None