Chapter 22 Authentication & Accounting
Table 60 Supported VSAs
FUNCTION | ATTRIBUTE |
|
|
Egress Bandwidth | |
Assignment | |
| |
Privilege Assignment | |
| |
| |
| or |
| |
| |
| |
| where N is a privilege level (from 0 to 14). |
| Note: If you set the privilege level of a login account differently |
| on the RADIUS server(s) and the Switch, the user is |
| assigned a privilege level from the database (RADIUS or |
| local) the Switch uses first for user authentication. |
|
|
22.2.4.1 Tunnel Protocol Attribute
You can configure tunnel protocol attributes on the RADIUS server (refer to your RADIUS server documentation) to assign a port on the Switch to a VLAN based on IEEE 802.1x authentication. The port VLAN settings are fixed and untagged. This will also set the port’s VID. The following table describes the values you need to configure. Note that the bolded values in the table are fixed values as defined in RFC 3580.
Table 61 Supported Tunnel Protocol Attribute
FUNCTIONATTRIBUTE
VLAN Assignment
Note: You must also create a VLAN with the specified VID on the Switch.
22.3 Supported RADIUS Attributes
Remote Authentication
Refer to RFC 2865 for more information about RADIUS attributes used for authentication. Refer to RFC 2866 and RFC 2869 for RADIUS attributes used for accounting.
This section lists the attributes used by authentication and accounting functions on the Switch. In cases where the attribute has a specific format associated with it, the format is specified.
178 |
| |
| ||
|
|
|