beautypg.com

Configuring multi-device port authentication, Configuring multi-device port authentication 7 – Brocade BigIron RX Series Configuration Guide User Manual

Page 1085

background image

BigIron RX Series Configuration Guide

1007

53-1002484-04

Configuring multi-device port authentication

32

To enable dynamic VLAN assignment for authenticated MAC addresses, you must add the following
attributes to the profile for the MAC address on the RADIUS server. Dynamic VLAN assignment on
multi-device port authentication-enabled interfaces is enabled by default.

In addition to dynamic VLAN assignment, BigIron RX Series also support dynamic ACL assignment
as is the case with 802.1x port security.

Support for authenticating multiple MAC addresses
on an interface

The multi-device port authentication feature allows multiple MAC addresses to be authenticated or
denied authentication on each interface. The maximum number of MAC addresses that can be
authenticated on each interface is 256. The default is 32.

Support for multi-device port authentication and 802.1x
on the same interface

On the BigIron RX, multi-device port authentication and 802.1x security can be enabled on the
same port. However, only one of them can authenticate a MAC address/802.1x client. If an 802.1x
client responds, the software assumes that the MAC should be authenticated using 802.1x
protocol mechanisms and multi-device port authentication for that MAC is aborted. Also, at any
given time, a port can have either 802.1x clients or multi-device port authentication clients but not
both.

Configuring multi-device port authentication

Configuring multi-device port authentication on the BigIron RX consists of the following tasks:

Enabling multi-device port authentication globally and on individual interfaces

Configuring an Authentication Method List for 802.1x

Setting RADIUS Parameters

Specifying the format of the MAC addresses sent to the RADIUS server (optional)

Specifying the authentication-failure action (optional)

Defining MAC address filters (optional)

Configuring dynamic VLAN assignment (optional)

Specifying to which VLAN a port is moved after its RADIUS-specified VLAN assignment expires
(optional)

Saving dynamic VLAN assignments to the running configuration file (optional)

Clearing authenticated MAC addresses (optional)

Attribute name

Type

Value

Tunnel-Type

064

13 (decimal) – VLAN

Tunnel-Medium-Type

065

6 (decimal) – 802

Tunnel-Private-Group-ID

081

<

vlan-name

>

(string) – either the name or the number of a

VLAN configured on the device.