Chapter 24 AAA
GS2200 Series User’s Guide
185
The following table describes the VSAs supported on the Switch.
24.6.1.1 Tunnel Protocol Attribute
You can configure tunnel protocol attributes on the RADIUS server (refer to your RADIUS server
documentation) to assign a port on the Switch to a VLAN based on IEEE 802.1x authentication. The
port VLAN settings are fixed and untagged. This will also set the port’s VID. The following table
describes the values you need to configure. Note that the bolded values in the table are fixed values
as defined in RFC 3580.
24.6.2 Supported RADIUS Attributes
Remote Authentication Dial-In User Service (RADIUS) attributes are data used to define specific
authentication elements in a user profile, which is stored on the RADIUS server. This appendix lists
the RADIUS attributes supported by the Switch.
Refer to RFC 2865 for more information about RADIUS attributes used for authentication.
This section lists the attributes used by authentication functions on the Switch. In cases where the
attribute has a specific format associated with it, the format is specified.
Table 65
Supported VSAs
FUNCTION
ATTRIBUTE
Ingress Bandwidth
Assignment
Vendor-Id =
890
Vendor-Type =
1
Vendor-data =
ingress rate (Kbps in decimal format)
Egress Bandwidth
Assignment
Vendor-Id =
890
Vendor-Type =
2
Vendor-data =
egress rate (Kbps in decimal format)
Privilege Assignment
Vendor-ID =
890
Vendor-Type =
3
Vendor-Data = "
shell:priv-lvl=
N"
or
Vendor-ID =
9
(CISCO)
Vendor-Type =
1
(CISCO-AVPAIR)
Vendor-Data = "
shell:priv-lvl=
N"
where
N
is a privilege level (from 0 to 14).
Note: If you set the privilege level of a login account differently on the RADIUS
server(s) and the Switch, the user is assigned a privilege level from the
database (RADIUS or local) the Switch uses first for user authentication.
Table 66
Supported Tunnel Protocol Attribute
FUNCTION
ATTRIBUTE
VLAN Assignment
Tunnel-Type =
VLAN(13)
Tunnel-Medium-Type =
802(6)
Tunnel-Private-Group-ID =
VLAN ID
Note: You must also create a VLAN with the specified VID on the Switch.
Содержание GS2200 Series
Страница 15: ...15 PART I User s Guide...
Страница 16: ...16...
Страница 31: ...31 PART II Technical Reference...
Страница 32: ...32...
Страница 76: ...Chapter 8 Basic Setting GS2200 Series User s Guide 76...
Страница 92: ...Chapter 9 VLAN GS2200 Series User s Guide 92 Figure 60 Port Based VLAN Setup Port Isolation...
Страница 230: ...Chapter 29 Error Disable GS2200 Series User s Guide 230...
Страница 248: ...Chapter 33 ARP Learning GS2200 Series User s Guide 248...
Страница 302: ...Appendix A Changing a Fuse GS2200 Series User s Guide 302...
Страница 306: ...Appendix B Common Services GS2200 Series User s Guide 306...
Страница 309: ...Appendix C Legal Information GS2200 Series User s Guide 309 ROHS...
Страница 310: ...Appendix C Legal Information GS2200 Series User s Guide 310...
Страница 320: ...Index GS2200 Series User s Guide 320...