beautypg.com

Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 244

background image

FIGURE 9 Sample MAC-based VLAN configuration

Host A MAC address is statically mapped to VLAN 1 with priority 1 and is not subjected to RADIUS
authentication. When Host B MAC address is authenticated, the Access-Accept message from the
RADIUS server specifies that Host B MAC address be placed into VLAN 2. Since Host C MAC
address is not present in the RADIUS server, Host C will be rejected by the server and its MAC
address will be placed into a restricted VLAN.

Below is the configuration for this example.

module 1 fcx-48-port-management-module

module 2 fcx-xfp-1-cx4-1-port-10g-module

vlan 1 by port

untagged ethe 0/1/10

mac-vlan-permit ethe 0/1/1 to 0/1/2

no spanning-tree

vlan 2 by port

untagged ethe 0/1/30

mac-vlan-permit ethe 0/1/1 to 0/1/2

no spanning-tree

vlan 666 name mac_restricted by port

untagged ethe 0/1/20

mac-vlan-permit ethe 0/1/1 to 0/1/2

no spanning-tree

vlan 4000 name DEFAULT-VLAN by port

no spanning-tree

vlan 4004 by port

mac-vlan-permit ethe 0/1/1

default-vlan-id 4000

ip address 10.44.3.8 255.255.255.0

ip default-gateway 10.44.3.1

MAC-based VLANs

244

FastIron Ethernet Switch Security Configuration Guide

53-1003088-03