Chapter 26 AAA
XGS4600 Series User’s Guide
291
• Assign account privilege levels (See the CLI Reference Guide for more information on account
privilege levels) for the authenticated user.
The VSAs are composed of the following:
•
Vendor-ID
: An identification number assigned to the company by the IANA (Internet Assigned
Numbers Authority). Zyxel’s vendor ID is 890.
•
Vendor-Type
: A vendor specified attribute, identifying the setting you want to modify.
•
Vendor-data
: A value you want to assign to the setting.
Note: Refer to the documentation that comes with your RADIUS server on how to configure
VSAs for users authenticating through the RADIUS server.
The following table describes the VSAs supported on the Switch. Note that these attributes only work
when you enable authorization (see
).
26.6.1.1 Tunnel Protocol Attribute
You can configure tunnel protocol attributes on the RADIUS server (refer to your RADIUS server
documentation) to assign a port on the Switch to a VLAN based on IEEE 802.1x authentication. The port
VLAN settings are fixed and untagged. This will also set the port’s VID. The following table describes the
values you need to configure. Note that these attributes only work when you enable authorization (see
).
Table 117 Supported VSAs
FUNCTION
ATTRIBUTE
Ingress Bandwidth
Assignment
Vendor-Id =
890
Vendor-Type =
1
Vendor-data =
ingress rate (Kbps in decimal format)
Egress Bandwidth
Assignment
Vendor-Id =
890
Vendor-Type =
2
Vendor-data =
egress rate (Kbps in decimal format)
Privilege Assignment
Vendor-ID =
890
Vendor-Type =
3
Vendor-Data = "
shell:priv-lvl=
N"
or
Vendor-ID =
9
(CISCO)
Vendor-Type =
1
(CISCO-AVPAIR)
Vendor-Data = "
shell:priv-lvl=
N"
where
N
is a privilege level (from 0 to 14).
Note: If you set the privilege level of a login account differently on the RADIUS
servers and the Switch, the user is assigned a privilege level from the
database (RADIUS or local) the Switch uses first for user authentication.
Содержание XGS4600 Series
Страница 24: ...24 PART I User s Guide ...
Страница 44: ...44 PART II Technical Reference ...
Страница 180: ...Chapter 13 Spanning Tree Protocol XGS4600 Series User s Guide 180 Figure 145 MSTP and Legacy RSTP Network Example ...
Страница 189: ...Chapter 16 Mirroring XGS4600 Series User s Guide 189 Figure 150 Advanced Application Mirroring Standalone Mode ...
Страница 244: ...Chapter 22 Policy Rule XGS4600 Series User s Guide 244 Figure 189 Policy Example EXAMPLE ...
Страница 277: ...Chapter 25 Multicast XGS4600 Series User s Guide 277 Figure 215 Advanced Application Multicast MVR Standalone Mode ...
Страница 559: ...Chapter 59 Access Control XGS4600 Series User s Guide 559 Figure 460 Example Lock Denoting a Secure Connection EXAMPLE ...
Страница 586: ...Chapter 69 Configure Clone XGS4600 Series User s Guide 586 Figure 479 Management Configure Clone Standalone Mode ...
Страница 587: ...Chapter 69 Configure Clone XGS4600 Series User s Guide 587 Figure 480 Management Configure Clone Stacking Mode ...
Страница 594: ...Chapter 71 Port Status XGS4600 Series User s Guide 594 Figure 485 Management Port Status Port Details Standalone Mode ...
Страница 604: ...604 PART III Troubleshooting and Appendices ...