Configuring multi-device port authentication, Configuring multi-device port authentication 7 – Brocade BigIron RX Series Configuration Guide User Manual
Page 1085
BigIron RX Series Configuration Guide
1007
53-1002484-04
Configuring multi-device port authentication
32
To enable dynamic VLAN assignment for authenticated MAC addresses, you must add the following
attributes to the profile for the MAC address on the RADIUS server. Dynamic VLAN assignment on
multi-device port authentication-enabled interfaces is enabled by default.
In addition to dynamic VLAN assignment, BigIron RX Series also support dynamic ACL assignment
as is the case with 802.1x port security.
Support for authenticating multiple MAC addresses
on an interface
The multi-device port authentication feature allows multiple MAC addresses to be authenticated or
denied authentication on each interface. The maximum number of MAC addresses that can be
authenticated on each interface is 256. The default is 32.
Support for multi-device port authentication and 802.1x
on the same interface
On the BigIron RX, multi-device port authentication and 802.1x security can be enabled on the
same port. However, only one of them can authenticate a MAC address/802.1x client. If an 802.1x
client responds, the software assumes that the MAC should be authenticated using 802.1x
protocol mechanisms and multi-device port authentication for that MAC is aborted. Also, at any
given time, a port can have either 802.1x clients or multi-device port authentication clients but not
both.
Configuring multi-device port authentication
Configuring multi-device port authentication on the BigIron RX consists of the following tasks:
•
Enabling multi-device port authentication globally and on individual interfaces
•
Configuring an Authentication Method List for 802.1x
•
Setting RADIUS Parameters
•
Specifying the format of the MAC addresses sent to the RADIUS server (optional)
•
Specifying the authentication-failure action (optional)
•
Defining MAC address filters (optional)
•
Configuring dynamic VLAN assignment (optional)
•
Specifying to which VLAN a port is moved after its RADIUS-specified VLAN assignment expires
(optional)
•
Saving dynamic VLAN assignments to the running configuration file (optional)
•
Clearing authenticated MAC addresses (optional)
Attribute name
Type
Value
Tunnel-Type
064
13 (decimal) – VLAN
Tunnel-Medium-Type
065
6 (decimal) – 802
Tunnel-Private-Group-ID
081
<
vlan-name
>
(string) – either the name or the number of a
VLAN configured on the device.