74
Using the Business Policy Switch 2000 Version 1.2
When the EAPOL-based security is disabled on a port that was previously
authorized, the port’s VLAN configuration values are restored directly from the
switch’s non-volatile random access memory (NVRAM).
The following exceptions apply to dynamic VLAN assignments:
•The dynamic VLAN configuration values assigned by EAPOL are not stored
in the switch’s NVRAM.
•You can override the dynamic VLAN configuration values assigned by
EAPOL; however, be aware that the values you configure are not stored in
NVRAM.
•When EAPOL is enabled on a port, and you configure values other than
VLAN configuration values, those values are applied and stored in NVRAM.
You set up your Authentication server (RADIUS server) for EAPOL dynamic
VLAN assignments. The Authentication server allows you to configure
user-specific settings for VLAN memberships and port priority.
When you log on to a system that has been configured for EAPOL authentication,
the Authentication server recognizes your user ID and notif ies the switch t o ass ign
preconfigured (user-specific) VLAN member ship and port priorities to the switch.
The configuration settings are based on configuration parameters that were
customized for your user ID and previously stored on the Authentication server.
To set up the Authentication server, set the following “Return List” attributes for
all user configurations (refer to your Authentication server documentation):
•VLAN membership attributes
—Tunnel-Type: value 13, Tunnel-Type-VLAN
—Tunnel-Medium-Type: value 6, Tunnel-Medium-Type-802
—Tunnel-Private-Group-Id: ASCII value 1 to 4094 (this value is used to
identify the specified VLAN)
•Port priority (vendor-specific) attributes
—Vendor Id: value 562, Nortel Networks vendor Id
—Attribute Number: value 1, Port Priority