Chapter 25 AAA
GS2210 Series User’s Guide
220
The follow ing t able descr ibes t he VSAs suppor t ed on t he Sw it ch.
25.6.1.1 Tunnel Protocol Attribute
You can configur e t unnel pr ot ocol at t r ibut es on t he RADI US ser ver ( r efer t o your RADI US ser ver
docum ent at ion) t o assign a por t on t he Sw it ch t o a VLAN based on I EEE 802.1x aut hent icat ion. The
por t VLAN set t ings ar e fixed and unt agged. This w ill also set t he por t ’s VI D. The follow ing t able
describes t he values you need t o configur e. Not e t hat t he bolded values in t he t able ar e fixed values
as defined in RFC 3580.
25.6.2 Supported RADIUS Attributes
Rem ot e Aut hent icat ion Dial- I n User Ser vice ( RADI US) at t r ibut es ar e dat a used t o define specific
aut hent icat ion elem ent s in a user pr ofile, w hich is st or ed on t he RADI US ser ver. This appendix list s
t he RADI US at t r ibut es suppor t ed by t he Swit ch.
Refer t o RFC 2865 for m or e infor m at ion about RADI US at t r ibut es used for aut hent icat ion.
This sect ion list s t he at t r ibut es used by aut hent icat ion funct ions on t he Sw it ch. I n cases w her e t he
at t r ibut e has a specific for m at associat ed w it h it , t he for m at is specified.
Table 95
Suppor t ed VSAs
FUNCTION
ATTRIBUTE
I ngr ess Bandw idt h
Assignm ent
Vendor-Id =
890
Vendor-Type =
1
Vendor-data =
ingress rate (Kbps in decimal format)
Egr ess Bandw idt h
Assignm ent
Vendor-Id =
890
Vendor-Type =
2
Vendor-data =
egress rate (Kbps in decimal format)
Pr ivilege Assignm ent
Vendor-ID =
890
Vendor-Type =
3
Vendor-Data = "
shell:priv-lvl=
N"
or
Vendor-ID =
9
(CISCO)
Vendor-Type =
1
(CISCO-AVPAIR)
Vendor-Data = "
shell:priv-lvl=
N"
w her e
N
is a pr iv ilege level ( fr om 0 t o 14) .
Note: If you set the privilege level of a login account differently on the RADIUS server(s)
and the Switch, the user is assigned a privilege level from the database (RADIUS
or local) the Switch uses first for user authentication.
Table 96
Suppor t ed Tunnel Pr ot ocol At t ribut e
FUNCTION
ATTRIBUTE
VLAN Assignm ent
Tunnel-Type =
VLAN(13)
Tunnel-Medium-Type =
802(6)
Tunnel-Private-Group-ID =
VLAN ID
Note: You must also create a VLAN with the specified VID on the Switch.