Note: Refer to the documentation that comes with your RADIUS server on how to configure a VSA.
The following table describes the VSAs supported on the switch.
Table 33 Supported VSA
FUNCTION | ATTRIBUTE |
|
|
Ingress Bandwidth | |
Assignment | |
| |
Egress Bandwidth | |
Assignment | |
| |
Privilege Assignment | |
| |
| |
| or |
| |
| |
| |
| where N is a privilege level (from 0 to 14). |
| Note: If you set the privilege level of a login account differently |
| on the RADIUS server(s) and the switch, the user is |
| assigned a privilege level from the database (RADIUS or |
| local) the switch uses first for user authentication. |
|
|
16.1.1.2 Tunnel Protocol Attribute
You can configure tunnel protocol attributes on the RADIUS server to assign a port on the switch to a VLAN (fixed, untagged). This will also set the port’s VID. Refer to RFC 3580 for more information.
Table 34 Supported Tunnel Protocol Attribute
FUNCTIONATTRIBUTE
VLAN Assignment
Note: You must also create a VLAN with the specified VID on the switch.
16.2 Port Authentication Configuration
To enable port authentication, first activate IEEE802.1x security (both on the switch and the port(s)) then configure the RADIUS server settings.
132 | Chapter 16 Port Authentication |