Chapter 20 Authentication & Accounting
ONU User’s Guide
154
20.1.6.1 Tunnel Protocol Attribute
You can configure tunnel protocol attributes on the RADIUS server (refer to your RADIUS
server documentation) to assign a port on the ONU to a VLAN based on IEEE 802.1x
authentication. The port VLAN settings are fixed and untagged. This will also set the port’s
VID. The following table describes the values you need to configure. Note that the bolded
values in the table are fixed values as defined in RFC 3580.
20.2 Supported RADIUS Attributes
Remote Authentication Dial-In User Service (RADIUS) attributes are data used to define
specific authentication, and accounting elements in a user profile, which is stored on the
RADIUS server. This appendix lists the RADIUS attributes supported by the ONU.
Refer to RFC 2865 for more information about RADIUS attributes used for authentication.
Refer to RFC 2866 and RFC 2869 for RADIUS attributes used for accounting.
This appendix lists the attributes used by authentication and accounting functions on the ONU.
In cases where the attribute has a specific format associated with it, the format is specified.
Egress Bandwidth
Assignment
Vendor-Id =
890
Vendor-Type =
2
Vendor-data =
egress rate (Kbps in decimal format)
Privilege Assignment
Vendor-ID =
890
Vendor-Type =
3
Vendor-Data = "
shell:priv-lvl=
N"
or
Vendor-ID =
9
(CISCO)
Vendor-Type =
1
(CISCO-AVPAIR)
Vendor-Data = "
shell:priv-lvl=
N"
where
N
is a privilege level (from 0 to 14).
Note: If you set the privilege level of a login account differently
on the RADIUS server(s) and the ONU, the user is
assigned a privilege level from the database (RADIUS or
local) the ONU uses first for user authentication.
Table 50
Supported VSAs
FUNCTION
ATTRIBUTE
Table 51
Supported Tunnel Protocol Attribute
FUNCTION
ATTRIBUTE
VLAN Assignment
Tunnel-Type =
VLAN(13)
Tunnel-Medium-Type =
802(6)
Tunnel-Private-Group-ID =
VLAN ID
Note: You must also create a VLAN with the specified VID on
the ONU.
Summary of Contents for ONU-2024 Series
Page 2: ......
Page 7: ...Safety Warnings ONU User s Guide 7 This product is recyclable Dispose of it properly...
Page 8: ...Safety Warnings ONU User s Guide 8...
Page 20: ...Table of Contents ONU User s Guide 20...
Page 28: ...List of Tables ONU User s Guide 28...
Page 30: ...30...
Page 38: ...Chapter 2 Hardware Installation and Connection ONU User s Guide 38...
Page 44: ...Chapter 3 Hardware Connections ONU User s Guide 44...
Page 46: ...46...
Page 64: ...Chapter 6 System Status and Port Statistics ONU User s Guide 64...
Page 76: ...Chapter 7 Basic Setting ONU User s Guide 76...
Page 78: ...78...
Page 108: ...Chapter 11 Spanning Tree Protocol ONU User s Guide 108...
Page 158: ...Chapter 20 Authentication Accounting ONU User s Guide 158...
Page 174: ...Chapter 22 Loop Guard ONU User s Guide 174...
Page 175: ...175 PART IV IP Application Static Route 177 Differentiated Services 181 DHCP 185...
Page 176: ...176...
Page 180: ...Chapter 23 Static Route ONU User s Guide 180...
Page 192: ...192...
Page 216: ...Chapter 27 Access Control ONU User s Guide 216...
Page 222: ...Chapter 29 Syslog ONU User s Guide 222...
Page 236: ...236...
Page 254: ...Appendix C Legal Information ONU User s Guide 254...
Page 260: ...Appendix D Customer Support ONU User s Guide 260...
Page 268: ...Index ONU User s Guide 268...