Configuring VLAN Authorization (RFC 3580)
D-Series CLI Reference 15-41
Parameters
Defaults
Ifnoauthenticationmethodisspecified,thesessiontimeoutvalueisresettoitsdefaultvalueof0
forallauthenticationmethods.
Mode
Switchmode,readwrite.
Example
ThisexampleresetsthesessiontimeoutvaluefortheIEEE802.1Xauthenticationmethodto0
seconds.
D2(su)->clear multiauth session-timeout dot1x
Configuring VLAN Authorization (RFC 3580)
Purpose
RFC3580TunnelAttributesprovideamechanismtocontainan802.1XauthenticatedoraMAC
authenticatedusertoaVLANregardlessofthePVID.
Pleaseseesection331ofRFC3580fordetailsonconfiguringaRADIUSservertoreturnthe
desiredtunnelattributes.AsstatedinRFC3580,“...itmaybedesirabletoallowaporttobeplaced
intoaparticularVirtualLAN(VLAN),definedin[IEEE8021Q],basedontheresultofthe
authentication.”
TheRADIUSservertypicallyindicatesthedesiredVLANbyincludingtunnelattributeswithinits
AccessAcceptparameters.However,theIEEE802.1XorMACauthenticatorcanalsobe
configuredtoinstructtheVLANtobeassignedtothesupplicantbyincludingtunnelattributes
withinAccessRequestparameters.
ThefollowingtunnelattributesareusedinVLANauthorizationassignment,:
•TunnelTy pe‐VLAN(13)
•TunnelMediumTy pe‐802
•TunnelPrivateGroupID‐VLANID
InordertoauthenticatemultipleRFC3580users,���policymaptableresponsemustbesettotunnel
asdescribedinthissection.
dot1x(Optional)SpecifiestheIEEE802.1Xportbasednetworkaccesscontrol
authenticationmethodforwhichtoresetthetimeoutvaluetoits
default.
mac (Optional)SpecifiestheEnterasysMACauthenticationmethodfor
whichtoresetthetimeoutvaluetoitsdefault.
pwa (Optional)SpecifiestheEnterasysPortWeb Authenticationmethodfor
whichtoresetthetimeoutvaluetoitsdefault.
Note: The D2 cannot simultaneously support Policy and RFC 3580 on the same port. If multiple
users are configured to use a port, and the G3 is then switched from "policy" mode to (RFC-3580
"tunnel" mode, the total number of users supported to use a port will be reset to one.