Configuring RFC 3580 show vlanauthorization
25-60 Authentication Configuration

Configuring RFC 3580

About RFC 3580

RFC3580providessuggestionsonhow802.1xAuthenticatorsshouldleverageRADIUSasthe
backendAAAinfrastructure.RFC3580isdividedintoseveralmajorsections:RADIUS
Accounting,RADIUSAuthentication,RC4EAPOLKeyFrameDiscussions,andSecurity
Considerations.Upondetection,EndPoints(PCs,IPPhones,etc.)maybeinterrogatedbythe
AAAclientsforcredentials,whichmaythenbeusedtoauthenticatetheuseranddeterminethe
serviceswhichshouldbeprovided(authorization).DuringtheexchangewiththeAAAserver,the
AAAclientwillpresentinformationdescribingtheEndPointanditself.TheAAAserverwillthen
describethelevelofservicewhichshouldbeprovided.Thismayincludeauthenticationsuccess,
sessionduration,andclassofservicetobeprovided.
EnterasysNetworksLayer2switchesutilizetwospecificattributestoimplementtheprovisioning
ofserviceinresponsetoasuccessfulauthentication:
•AproprietaryFilterID,whichdescribesaPolicyProfiletobeappliedtotheuser.(See
RADIUSFilterIDAttributeandDynamicPolicyProfileAssignmentonpage 2550.)
•TheVLANTunnelAttribute;whichdefinesthebaseVLANIDtobeappliedtotheuser(or
possiblymappedtoanEnterasysPolicyProfile).
Purpose
ToreviewandconfigureRFC3580support.
Commands

show vlanauthorization

UsethiscommandtodisplaytheVLANAuthorizationsettings.
Syntax
show vlanauthorization [port-list] | [all]
Parameters
Defaults
Ifnoparametersarespecified,allVLANAuthorizationconfigurationinformationwillbe
displayed.
For information about... Refer to page...
show vlanauthorization 25-60
set vlanauthorization 25-61
clear vlanauthorization 25-62
portlist (Optional)Displaystheport(s)VLANAuthorizationsettings.
all (Optional)Displaysallport(s)VLANAuthorizationsettings.