Falcon
M-Class
| User Guide
154
RADIUS-
Assigned VLAN
Enabled
When RADIUS-Assigned VLAN is both globally enabled and enabled
(checked) for a given port, the switch reacts to VLAN ID information
carried in the RADIUS Access-Accept packet transmitted by the RADIUS
server when a supplicant is successfully authenticated. If present and
valid, the port's Port VLAN ID will be changed to this VLAN ID, the port
will be set to be a member of that VLAN ID, and the port will be forced
into VLAN unaware mode. Once assigned, all traffic arriving on the port
will be classified and switched on the RADIUS-assigned VLAN ID.
If (re-)authentication fails or the RADIUS Access-Accept packet no
longer carries a VLAN ID or it's invalid, or the supplicant is otherwise no
longer present on the port, the port's VLAN ID is immediately reverted
to the original VLAN ID (which may be changed by the administrator in
the meanwhile without affecting the RADIUS-assigned).
This option is only available for single-client modes, i.e.
•
Port-based 802.1X
• Single 802.1X
For trouble-shooting VLAN assignments, use the " VLANs
→
VLAN
Membership Status
and
which modules have (temporarily) overridden the current Port VLAN
configuration.
RADIUS attributes used in identifying a VLAN ID:
and
form the basis for the attributes used in
identifying a VLAN ID in an Access-Accept packet. The following criteria
are used:
The Tunnel-Medium-Type, Tunnel-Type, and Tunnel-Private-Group-
IDattributes must all be present at least once in the Access-Accept
packet.
The switch looks for the first set of these attributes that have the same
Tag value and fulfil the following requirements (if Tag == 0 is used, the
Tunnel-Private-Group-IDdoes not need to include a Tag):
- Value of Tunnel-Medium-Type must be set to "IEEE-802" (ordinal 6).
- Value of Tunnel-Type must be set to "VLAN" (ordinal 13).
- Value of Tunnel-Private-Group-ID must be a string of ASCII chars in
the range '0' - '9', which is interpreted as a decimal string representing
the VLAN ID. Leading '0's are discarded. The final value must be in the
range [1; 4095].
Summary of Contents for Falcon Gen-3 M-Class
Page 90: ...Falcon M Class User Guide 90...
Page 107: ...Falcon M Class User Guide 107 Figure 4 57 DSCP Translation...
Page 139: ...Falcon M Class User Guide 139...
Page 187: ...Falcon M Class User Guide 187 Figure 4 99 RADIUS Statistics for Server...
Page 197: ...Falcon M Class User Guide 197 4 11 6 SyncCenter Status Figure 4 104 Sync Center Status...
Page 214: ...Falcon M Class User Guide 214...
Page 227: ...Falcon M Class User Guide 227...
Page 234: ...Falcon M Class User Guide 234...
Page 358: ...Falcon M Class User Guide 358 Figure 4 216 sFlow Configuration displays...
Page 376: ...Falcon M Class User Guide 376...
Page 403: ...Falcon M Class User Guide 403...