
Managing Authentication Servers
RADIUS Servers
OmniSwitch 6624/6648 Network Configuration Guide
April 2004
page 17-11
Vendor-Specific Attributes for RADIUS
The Alcatel RADIUS client supports attribute 26, which includes a vendor ID and some additional sub-
attributes called subtypes. The vendor ID and the subtypes collectively are called Vendor Specific
Attributes (VSAs). Alcatel, through partnering arrangements, has included these VSAs in some vendors’
RADIUS server configurations.
The attribute subtypes are defined in the server’s dictionary file. If you are using single authority mode,
the first VSA subtype, Alcatel-Auth-Vlan, must be defined on the server for each authenticated VLAN.
Alcatel’s vendor ID is 800 (SMI Network Management Private Enterprise Code).
The following are VSAs for RADIUS servers:
The Alcatel-Auth-Group attribute is used for Ethernet II only. If a different protocol, or more than one
protocol is required, use the Alcatel-Auth-Group-Protocol attribute instead. For example:
Alcatel-Auth-Group-Protocol 23: IP_E2 IP_SNAP
Alcatel-Auth-Group-Protocol 24: IPX_E2
In this example, authenticated users on VLAN 23 may use Ethernet II or SNAP encapsulation. Authenti-
cated users on VLAN 24 may use IPX with Ethernet II.
Num. RADIUS VSA
Type
Description
1 Alcatel-Auth-Group
integer
The authenticated VLAN number. The only protocol
associated with this attribute is Ethernet II. If other
protocols are required, use the protocol attribute
instead.
2 Alcatel-Slot-Port
string
Slot(s)/port(s) valid for the user.
3 Alcatel-Time-of-Day
string
The time of day valid for the user to authenticate.
4 Alcatel-Client-IP-Addr
address
The IP address used for Telnet only.
5 Alcatel-Group-Desc
string
Description of the authenticated VLAN.
6 Alcatel-Port-Desc
string
Description of the port.
8 Alcatel-Auth-Group-Protocol
string
The protocol associated with the VLAN. Must be
configured for access to other protocols. Values
include:
IP_E2
,
IP_SNAP
,
IPX_E2
,
IPX_NOV
,
IPX_LLC
,
IPX_SNAP
.
9 Alcatel-Asa-Access
string
Specifies that the user has access to the switch. The
only valid value is
all
.
39 Alcatel-Acce-Priv-F-R1
hex.
Configures functional read privileges for the user.
40 Alcatel-Acce-Priv-F-R2
hex.
Configures functional read privileges for the user.
41 Alcatel-Acce-Priv-F-W1
hex.
Configures functional write privileges for the user.
42 Alcatel-Acce-Priv-F-W2
hex.
Configures functional write privileges for the user.
Содержание OmniSwitch 6624
Страница 1: ...Part No 060179 10 Rev C April 2004 OmniSwitch 6624 6648 Network Configuration Guide www alcatel com...
Страница 22: ...Contents xxii OmniSwitch 6624 6648 Network Configuration Guide April 2004...
Страница 174: ...Verifying 802 1Q Configuration Configuring 802 1Q page 9 12 OmniSwitch 6624 6648 Network Configuration Guide April 2004...
Страница 264: ...Verifying the RIP Configuration Configuring RIP page 13 16 OmniSwitch 6624 6648 Network Configuration Guide April 2004...
Страница 276: ...Verifying the RDP Configuration Configuring RDP page 14 12 OmniSwitch 6624 6648 Network Configuration Guide April 2004...