Network Login
ExtremeWare XOS 11.1 Concepts Guide
231
Table 40
contains the Vendor Specific Attribute (VSA) definitions for web-based and 802.1x network
login. The Extreme Network Vendor ID is 1916.
The
NetLogin-Url
and
NetLogin-Url-Desc
attributes are used in case of Web-based login as the page to
use for redirection after a successful login. Other authentication methods will ignore these attributes.
The other attributes are used in the following order to determine the destination VLAN to use:
●
Extreme: NetLogin-VLAN-Name (VSA 203)
●
Extreme: NetLogin-VLAN-ID (VSA 209)
●
IETF: Tunnel-Private-Group-Id representing the VLAN TAG as a string, but only if IETF: Tunnel
Type == VLAN(13) and IETF: Tunnel Medium == 802 (6).
If none of them are present ISP mode is assumed, and the client will remain in the configured VLAN.
Interoperability Requirements
For network login to operate, the user (supplicant) software and the authentication server must support
common authentication methods. Not all combinations provide the appropriate functionality.
Supplicant Side
The supported 802.1x clients (supplicants) are Windows 2000 SP4 native client, Windows XP native
clients, and Meetinghouse AEGIS. Supported authentication types are MD5, TLS, TTLS, and PEAP.
Table 40: VSA Definitions for Web-based and 802.1x Network Login
VSA
Attribute
Value
Type
Sent-in
Description
Extreme: Netlogin-
VLAN-Name
203
String
Access-Accept
Name of destination VLAN after successful
authentication (must already exist on switch).
Extreme: Netlogin-
VLAN-ID
209
Integer
Access-Accept
ID of destination VLAN after successful
authentication (must already exist on switch).
Extreme: Netlogin-URL
204
String
Access-Accept
Destination web page after successful
authentication.
Extreme: Netlogin-
URL-Desc
205
String
Access-Accept
Text description of network login URL
attribute.
Extreme: Netlogin-Only
206
Integer
Access-Accept
Indication of whether the user can
authenticate using other means, such as
telnet, console, SSH, or Vista. A value of “1”
(enabled) indicates that the user can only
authenticate via network login. A value of zero
(disabled) indicates that the user can also
authenticate via other methods.
Tunnel-Private-Group-
ID
IETF: Tunnel Type
64
IETF: Tunnel Medium
65
IETF: Tunnel-Private
Group-ID
81
Summary of Contents for ExtremeWare XOS 11.1
Page 16: ...Contents ExtremeWare XOS 11 1 Concepts Guide 16...
Page 20: ...Preface ExtremeWare XOS 11 1 Concepts Guide 20...
Page 21: ...1 Using ExtremeWare XOS...
Page 22: ......
Page 78: ...Managing the ExtremeWare XOS Software ExtremeWare XOS 11 1 Concepts Guide 78...
Page 168: ...Virtual LANs ExtremeWare XOS 11 1 Concepts Guide 168...
Page 200: ...Policies and ACLs ExtremeWare XOS 11 1 Concepts Guide 200...
Page 252: ...Security ExtremeWare XOS 11 1 Concepts Guide 252...
Page 265: ...2 Using Switching and Routing Protocols...
Page 266: ......
Page 294: ...Ethernet Automatic Protection Switching ExtremeWare XOS 11 1 Concepts Guide 294...
Page 354: ...Extreme Standby Router Protocol ExtremeWare XOS 11 1 Concepts Guide 354...
Page 416: ...IP Multicast Routing ExtremeWare XOS 11 1 Concepts Guide 416...
Page 417: ...3 Appendixes...
Page 418: ......
Page 432: ...Software Upgrade and Boot Options ExtremeWare XOS 11 1 Concepts Guide 432...