PowerConnect B-Series FCX Configuration Guide
1231
53-1002266-01
Configuring 802.1X port security
34
NOTE
When a show run command is issued during a session, the dynamically-assigned VLAN is not
displayed.
Enable 802.1X VLAN ID support by adding the following attributes to a user profile on the RADIUS
server.
The device reads the attributes as follows:
•
If the Tunnel-Type or the Tunnel-Medium-Type attributes in the Access-Accept message do not
have the values specified above, the Dell PowerConnect device ignores the three
Attribute-Value pairs. The client becomes authorized, but the client port is not dynamically
placed in a VLAN.
•
If the Tunnel-Type or the Tunnel-Medium-Type attributes in the Access-Accept message do have
the values specified above, but there is no value specified for the Tunnel-Private-Group-ID
attribute, the client will not become authorized.
•
When the Dell PowerConnect device receives the value specified for the
Tunnel-Private-Group-ID attribute, it checks whether the
<vlan-name>
string matches the
name of a VLAN configured on the device. If there is a VLAN on the device whose name
matches the
<vlan-name>
string, then the client port is placed in the VLAN whose ID
corresponds to the VLAN name.
•
If the
<vlan-name>
string does not match the name of a VLAN, the Dell PowerConnect device
checks whether the string, when converted to a number, matches the ID of a VLAN configured
on the device. If it does, then the client port is placed in the VLAN with that ID.
•
If the
<vlan-name>
string does not match either the name or the ID of a VLAN configured on
the device, then the client will not become authorized.
The show interface command displays the VLAN to which an 802.1X-enabled port has been
dynamically assigned, as well as the port from which it was moved (that is, the port default
VLAN).Refer to
“Displaying dynamically assigned VLAN information”
on page 1251 for sample
output indicating the port dynamically assigned VLAN.
Dynamic multiple VLAN assignment for 802.1X ports
When you add attributes to a user profile on the RADIUS server, the
<vlan-name>
value for the
Tunnel-Private-Group-ID attribute can specify the name or number of one or more VLANs configured
on the Dell PowerConnect device.
For example, to specify one VLAN, configure the following for the
<vlan-name>
value in the
Tunnel-Private-Group-ID attribute on the RADIUS server.
"10" or "marketing"
In this example, the port on which the Client is authenticated is assigned to VLAN 10 or the VLAN
named "marketing". The VLAN to which the port is assigned must have previously been configured
on the Dell PowerConnect device.
Attribute name
Type
Value
Tunnel-Type
064
13 (decimal) – VLAN
Tunnel-Medium-Type
065
6 (decimal) – 802
Tunnel-Private-Group-ID
081
<vlan-name>
(string) – either the name or the number of a VLAN
configured on the Dell PowerConnect device.
Summary of Contents for PowerConnect B-FCXs
Page 1: ...53 1002266 01 18 March 2011 PowerConnect B Series FCX Configuration Guide ...
Page 248: ...206 PowerConnect B Series FCX Configuration Guide 53 1002266 01 IPv6 management commands 7 ...
Page 374: ...332 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Jumbo frame support 9 ...
Page 568: ...526 PowerConnect B Series FCX Configuration Guide 53 1002266 01 CLI examples 14 ...
Page 588: ...546 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Sample application 15 ...
Page 684: ...642 PowerConnect B Series FCX Configuration Guide 53 1002266 01 VLAN based mirroring 20 ...
Page 724: ...682 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Reading CDP packets 23 ...
Page 930: ...888 PowerConnect B Series FCX Configuration Guide 53 1002266 01 26 ...
Page 948: ...906 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Configuring MLD snooping 27 ...
Page 1348: ...1306 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Example configurations 36 ...
Page 1406: ...1364 PowerConnect B Series FCX Configuration Guide 53 1002266 01 IP source guard 39 ...