xStack
®
DGS-3120 Series Layer 3 Managed Gigabit Ethernet Switch CLI Reference Guide
1143
Others
(0x00, 0x03 ~ 0x1F,
>0x1F)
1. When the switch receives the
VLAN setting string, it will think it is
the VLAN ID first. In other words, the
switch will check all existed VLAN ID
and check if there is one matched.
2. If the switch can find one
matched, it will move to that VLAN.
3. If the switch can not find the
matched VLAN ID, it will think the
VLAN setting string as a “VLAN
Name”.
4. Then it will check that it can find
out a matched VLAN Name.
following field.
If the user has configured the VLAN attribute of the RADIUS server (for example, VID 3) and the
802.1X, or MAC-based Access Control authentication is successful, the port will be added to VLAN
3. However, if the user does not configure the VLAN attribute and authenticates successfully, the
port will be kept in its original VLAN. If the VLAN attribute configured on the RADIUS server does
not exist, the port will not be assigned to the requested VLAN.
To assign
ACL by RADIUS Server
, the proper parameters should be configured on the RADIUS
Server. The table below shows the parameters for an ACL.
The parameters of the Vendor-Specific Attribute are:
RADIUS Tunnel
Attribute
Description
Value
Usage
Vendor-ID
Defines the vendor.
171 (DLINK)
Required
Vendor-Type
Defines the attribute.
12 (for ACL profile)
13 (for ACL rule)
Required
Attribute-Specific
Field
Used to assign the ACL
profile or rule.
ACL Command
For example:
ACL profile:
create access_profile
profile_id 6 profile_name 1 ethernet
vlan 0xFFF;
ACL rule:
config access_profile
profile_id 6 add access_id
auto_assign ethernet vlan_id 1 port
all deny;
Required
If the user has configured the ACL attribute of the RADIUS server (for example, ACL profile:
create access_profile profile_id 6 profile_name 1 ethernet
; ACL rule:
config access_profile
profile_id 6 add access_id auto_assign ethernet
), and the 802.1X, MAC-based Access Control,
WAC or JWAC authentication is successful, the device will assign the ACL profiles and rules
according to the RADIUS server. For more information about the ACL module, please refer to
Chapter 22 Access Control List (ACL) Commands.
Содержание xStack DGS-3120 Series
Страница 1: ......
Страница 186: ...xStack DGS 3120 Series Layer 3 Managed Gigabit Ethernet Switch CLI Reference Guide 181...
Страница 204: ...xStack DGS 3120 Series Layer 3 Managed Gigabit Ethernet Switch CLI Reference Guide 199...
Страница 363: ...xStack DGS 3120 Series Layer 3 Managed Gigabit Ethernet Switch CLI Reference Guide 358...
Страница 788: ...xStack DGS 3120 Series Layer 3 Managed Gigabit Ethernet Switch CLI Reference Guide 783 DGS 3120 24TC admin...
Страница 1056: ...xStack DGS 3120 Series Layer 3 Managed Gigabit Ethernet Switch CLI Reference Guide 1051...