![Juniper JUNOS OS 10.3 - SOFTWARE Manual Download Page 2722](http://html.mh-extra.com/html/juniper/junos-os-10-3-software/junos-os-10-3-software_manual_20327932722.webp)
user@switch#
set
fast-start
6
Related
Documentation
Configuring LLDP (J-Web Procedure) on page 2623
•
•
Example: Setting Up VoIP with 802.1X and LLDP-MED on an EX Series Switch on
page 2580
•
Configuring LLDP (CLI Procedure) on page 2622
•
Understanding 802.1X and LLDP and LLDP-MED on EX Series Switches on page 2540
VSA Match Conditions and Actions for EX Series Switches
EX Series switches support the configuration of RADIUS server attributes specific to
Juniper Networks. These attributes are known as vendor-specific attributes (VSAs). They
are configured on RADIUS servers and work in combination with 802.1X authentication.
Using VSAs, you can apply port firewall filter attributes as a subset of match conditions
and actions sent from the RADIUS server to the switch as a result of 802.1X authentication
success.
Each term in a VSA configured through the RADIUS server consists of
match conditions
and an
action
. Match conditions are the values or fields that the packet must contain.
You can define single, multiple, or no match conditions. If no match conditions are
specified for the term, the packet is accepted by default. The action is the action that
the switch takes if a packet matches the match conditions for the specific term. Allowed
actions are accept a packet or discard a packet.
The following guidelines apply when you specify match conditions and actions for VSAs:
•
Both
match
and
action
statements are mandatory.
•
Any or all options (separated by commas) may be included in each
match
and
action
statement.
•
Fields separated by commas will be ANDed if they are of a different type. The same
types cannot be repeated.
•
For OR cases (for example, match
10.1.1.0/24
OR
11.1.1.0/24
), apply multiple VSAs to
the 802.1X supplicant.
•
In order for the
forwarding-class
option to be applied, the forwarding class must be
configured on the switch. If it is not configured on the switch, this option is ignored.
Table 345 on page 2626 describes the match conditions you can specify when configuring
a VSA using the
match
command on the RADIUS server. The string that defines a match
condition is called a
match statement
.
Table 345: Match Conditions
Description
Option
Destination media access control (MAC) address of the packet.
destination-mac mac-address
Name of the source VLAN.
source-vlan source-vlan
Copyright © 2010, Juniper Networks, Inc.
2626
Complete Software Guide for Junos
®
OS for EX Series Ethernet Switches, Release 10.3
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...