D-Link DWS-3160-24TC DWS-3160 Series Web UI Reference Guide - Page 499

Known Client and MAC Authentication RADIUS Attributes, present then the Client QoS Default ACL Up

Page 499 highlights

DWS-3160 Series Gigabit Ethernet Unified Switch Web UI Reference Guide Client-ACL-Up (121) Vendor-Specific (26), D-Link (171), Client-Policy-Dn (122) Vendor-Specific (26), D-Link (171), Client-Policy-Up (123) Tunnel-Type (64) Tunnel-Medium-Type (65) Tunnel-Private-Group-ID (81) inbound (up) direction. If this attribute is not present then the Client QoS Default ACL Up Type and Name parameters defined in the Network configuration are used instead. If this attribute is present but refers to an undefined access list name in the system, all packets for this client will be dropped until the ACL is defined. Name of DiffServ policy to be applied to 802.1X authenticated wireless client traffic in the outbound (down) direction. If this attribute is not present then the Client QoS Default Policy Down parameter defined in the Network configuration is used instead. If this attribute is present but refers to an undefined policy name in the system, all packets for this client will be dropped until the DiffServ policy is defined. Name of DiffServ policy to be applied to 802.1X authenticated wireless client traffic in the inbound (up) direction. If this attribute is not present then the Client QoS Default Policy Up parameter defined in the Network configuration is used instead. If this attribute is present but refers to an undefined policy name in the system, all packets for this client will be dropped until the DiffServ policy is defined. For dynamic VLAN usage. For dynamic VLAN usage. For dynamic VLAN usage. terminated) The string is of the form "type:name" where: • type = ACL type identifier: IPV4, IPV6, MAC • : = required separator character • name = 1-31 alphanumeric characters, specifying the ACL number (IPV4) or name (IPV6, MAC) Type: string 1-31 characters (not nullterminated) Type: string 1-31 characters (not nullterminated) VLAN (13) 802 VLANID Optional Optional Optional Optional Optional Known Client and MAC Authentication RADIUS Attributes The database is used to retrieve client descriptive names from the RADIUS server as well as implement MAC Authentication. An Access Point can be configured to use MAC authentication via the RADIUS to allow or deny specific client stations access to the wireless network. This is less secure but can be used for client stations that do not support 802.1X. The following table indicates the attributes that are configured in the RADIUS server entry. Attribute User-Name (1) User-Password (2) Vendor-Specific (26), D-Link (171), MAC-Authentication-Action (114) Vendor-Specifc (26), D-Link (171), Client-Nickname (115) Description Ethernet Address of the client station. A fixed password used to lookup an client MAC entry. Flag indicating what action to take if MAC authentication is enabled on the network. Descriptive Name of the client. Range Valid Ethernet MAC Address. "NOPASSWORD" 0-Global Action 1-Grant Access 2-Deny Access 0-32 Character String 494 Usage Required Required Optional Optional Default None None 0 ""

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505

DWS-3160 Series Gigabit Ethernet Unified Switch Web UI Reference Guide
494
Client-ACL-Up (121)
inbound (up) direction. If this attribute is not
present then the Client QoS Default ACL Up
Type and Name parameters defined in the
Network configuration are used instead. If this
attribute is present but refers to an undefined
access list name in the system, all packets for
this client will be dropped until the ACL is
defined.
terminated) The
string is of the form
"type:name" where:
• type = ACL type
identifier: IPV4,
IPV6, MAC
• : = required
separator character
• name = 1-31
alphanumeric
characters,
specifying the ACL
number (IPV4) or
name (IPV6, MAC)
Vendor-Specific (26),
D-Link (171),
Client-Policy-Dn (122)
Name of DiffServ policy to be applied to
802.1X authenticated wireless client traffic in
the outbound (down) direction. If this attribute
is not present then the Client QoS Default
Policy Down parameter defined in the Network
configuration is used instead. If this attribute is
present but refers to an undefined policy name
in the system, all packets for this client will be
dropped until the DiffServ policy is defined.
Type: string 1-31
characters (not null-
terminated)
Optional
Vendor-Specific (26),
D-Link (171),
Client-Policy-Up (123)
Name of DiffServ policy to be applied to
802.1X authenticated wireless client traffic in
the inbound (up) direction. If this attribute is
not present then the Client QoS Default Policy
Up parameter defined in the Network
configuration is used instead. If this attribute is
present but refers to an undefined policy name
in the system, all packets for this client will be
dropped until the DiffServ policy is defined.
Type: string 1-31
characters (not null-
terminated)
Optional
Tunnel-Type (64)
For dynamic VLAN usage.
VLAN (13)
Optional
Tunnel-Medium-Type (65)
For dynamic VLAN usage.
802
Optional
Tunnel-Private-Group-ID
(81)
For dynamic VLAN usage.
VLANID
Optional
The database is used to retrieve client descriptive names from the RADIUS server as well as implement MAC
Authentication. An Access Point can be configured to use MAC authentication via the RADIUS to allow or deny
specific client stations access to the wireless network. This is less secure but can be used for client stations that do
not support 802.1X. The following table indicates the attributes that are configured in the RADIUS server entry.
Known Client and MAC Authentication RADIUS Attributes
Attribute
Description
Range
Usage
Default
User-Name (1)
Ethernet Address of the
client station.
Valid Ethernet MAC
Address.
Required
None
User-Password (2)
A fixed password used
to lookup an client MAC
entry.
“NOPASSWORD”
Required
None
Vendor-Specific (26),
D-Link (171),
MAC-Authentication-Action
(114)
Flag indicating what
action to take if MAC
authentication is enabled
on the network.
0-Global Action
1-Grant Access
2-Deny Access
Optional
0
Vendor-Specifc (26),
D-Link (171),
Client-Nickname (115)
Descriptive Name of the
client.
0-32 Character String
Optional
“”