D-Link DGS-1250 User Manual - Page 319

Appendix C - RADIUS Attributes Assignment

Page 319 highlights

DGS-1250 Series Gigabit Ethernet Smart Managed Switch Web UI Reference Guide Appendix C - RADIUS Attributes Assignment The RADIUS Attributes Assignment on the Switch is used in the 802.1X module. The descriptions that follow explain the VLAN RADIUS Attributes Assignment type. To assign the VLAN by the RADIUS server, the proper parameters should be configured on the RADIUS server. To use VLAN assignment, RFC 3580 defines the following tunnel attributes in RADIUS packets. The table below shows the parameters for a VLAN: RADIUS Tunnel Attribute Tunnel-Type Tunnel-Medium-Type Tunnel-Private-Group-ID Description This attribute indicates the tunneling protocol(s) to be used (in the case of a tunnel initiator) or the tunneling protocol in use (in the case of a tunnel terminator). This attribute indicates the transport medium being used. This attribute indicates group ID for a particular tunneled session. Value 13 (VLAN) 6 (802) A string (VID) Usage Required Required Required A summary of the Tunnel-Private-Group-ID Attribute format is shown below. 0 1 2 3 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 | Type | Length | Tag | String... The table below shows the definition of Tag field (different with RFC 2868): Tag field value 0x01 0x02 Others (0x00, 0x03 ~ 0x1F, >0x1F) String field format VLAN name (ASCII) VLAN ID (ASCII) When the Switch receives the VLAN setting string, it will think it is the VLAN ID first. In other words, the Switch will check all existing VLAN IDs and check if there is one matched. If the Switch can find one matched, it will move to that VLAN. If the Switch cannot find the matched VLAN ID, it will think the VLAN setting string as a "VLAN Name". Then it will check that it can find out a matched VLAN Name. NOTE: A tag field of greater than 0x1F is interpreted as the first octet of the following field. If the user has configured the VLAN attribute of the RADIUS server (for example, VID 3) and the 802.1X authentication is successful, the port will be assigned to VLAN 3. However if the user does not configure the VLAN attributes, when the port is not guest VLAN member, it will be kept in its current authentication VLAN, and when the port is guest VLAN member, it will be assigned to its original VLAN. 310

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320

DGS-1250 Series Gigabit Ethernet Smart Managed Switch Web UI Reference Guide
310
Appendix C - RADIUS Attributes Assignment
The RADIUS Attributes Assignment on the Switch is used in the 802.1X module. The descriptions that follow explain
the VLAN RADIUS Attributes Assignment type.
To assign the
VLAN
by the RADIUS server, the proper parameters should be configured on the RADIUS server. To
use VLAN assignment, RFC 3580 defines the following tunnel attributes in RADIUS packets.
The table below shows the parameters for a VLAN:
RADIUS Tunnel Attribute
Description
Value
Usage
Tunnel-Type
This attribute indicates the tunneling protocol(s) to be used
(in the case of a tunnel initiator) or the tunneling protocol in
use (in the case of a tunnel terminator).
13
(VLAN)
Required
Tunnel-Medium-Type
This attribute indicates the transport medium being used.
6 (802)
Required
Tunnel-Private-Group-ID
This attribute indicates group ID for a particular tunneled
session.
A string
(VID)
Required
A summary of the Tunnel-Private-Group-ID Attribute format is shown below.
0
1
2
3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|
Type
|
Length
|
Tag
|
String...
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
The table below shows the definition of Tag field (different with RFC 2868):
Tag field value
String field format
0x01
VLAN name (ASCII)
0x02
VLAN ID (ASCII)
Others
(0x00, 0x03 ~
0x1F, >0x1F)
When the Switch receives the VLAN setting string, it will think it is the VLAN ID first. In other
words, the Switch will check all existing VLAN IDs and check if there is one matched. If the
Switch can find one matched, it will move to that VLAN. If the Switch cannot find the matched
VLAN ID, it will think the VLAN setting string as a "VLAN Name". Then it will check that it can
find out a matched VLAN Name.
NOTE:
A tag field of greater than 0x1F is interpreted as the first octet of the following field.
If the user has configured the VLAN attribute of the RADIUS server (for example, VID 3) and the 802.1X
authentication is successful, the port will be assigned to VLAN 3. However if the user does not configure the VLAN
attributes, when the port is not guest VLAN member, it will be kept in its current authentication VLAN, and when the
port is guest VLAN member, it will be assigned to its original VLAN.