– 93 –
C
HAPTER
4
| Configuring the Switch
Configuring Security
RADIUS Attributes Used in Identifying a QoS Class
The User-Priority-Table attribute defined in RFC4675 forms the basis for
identifying the QoS Class in an Access-Accept packet.
Only the first occurrence of the attribute in the packet will be
considered. To be valid, all 8 octets in the attribute's value must be
identical and consist of ASCII characters in the range '0' - '3', which
translates into the desired QoS Class in the range 0-3.
QoS assignments to be applied to a switch port for an authenticated
user may be configured on the RADIUS server as described below:
■
The “Filter-ID” attribute (attribute 11) can be configured on the
RADIUS server to pass the following QoS information:
Table 7: Dynamic QoS Profiles
Profile Attribute
Syntax
Example
DiffServ
service-policy-in=policy-map-name service-policy-in=p1
Rate Limit rate-limit-input=rate
rate-limit-input=100
(in units of Kbps)
802.1p
switchport-priority-default=value switchport-priority-default=2
■
Multiple profiles can be specified in the Filter-ID attribute by using a
semicolon to separate each profile.
For example, the attribute “service-policy-in=pp1;rate-limit-
input=100” specifies that the diffserv profile name is “pp1,” and the
ingress rate limit profile value is 100 kbps.
■
If duplicate profiles are passed in the Filter-ID attribute, then only
the first profile is used.
For example, if the attribute is “service-policy-in=p1;service-policy-
in=p2”, then the switch applies only the DiffServ profile “p1.”
■
Any unsupported profiles in the Filter-ID attribute are ignored.
For example, if the attribute is “map-ip-dscp=2:3;service-policy-
in=p1,” then the switch ignores the “map-ip-dscp” profile.
■
When authentication is successful, the dynamic QoS information
may not be passed from the RADIUS server due to one of the
following conditions (authentication result remains unchanged):
■
The Filter-ID attribute cannot be found to carry the user profile.
■
The Filter-ID attribute is empty.
■
The Filter-ID attribute format for dynamic QoS assignment is
unrecognizable (can not recognize the whole Filter-ID attribute).
■
Dynamic QoS assignment fails and the authentication result
changes from success to failure when the following conditions
occur:
■
Illegal characters found in a profile value (for example, a non-
digital character in an 802.1p profile value).
Содержание EX26262
Страница 1: ...Layer 2 Gigabit PoE Ethernet Switch Management Guide...
Страница 2: ......
Страница 3: ...MANAGEMENT GUIDE...
Страница 4: ......
Страница 6: ...6 ABOUT THIS GUIDE...
Страница 18: ...18 FIGURES...
Страница 20: ...20 TABLES...
Страница 22: ...22 SECTION I Getting Started...
Страница 34: ...34 SECTION II Web Configuration...
Страница 46: ...46 CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface...
Страница 202: ...CHAPTER 4 Configuring the Switch Quality of Service 202 Figure 83 Configuring Port Tag Remarking Mode...
Страница 290: ...290 CHAPTER 5 Monitoring the Switch Displaying Information About Flow Sampling...
Страница 294: ...CHAPTER 6 Performing Basic Diagnostics Running Cable Diagnostics 294...
Страница 300: ...CHAPTER 7 Performing System Maintenance Managing Configuration Files 300...
Страница 302: ...302 SECTION III Appendices...
Страница 320: ...GLOSSARY 320...
Страница 325: ......
Страница 326: ......