Dell PowerConnect M6348 Configuration Guide - Page 105

Authentication Server Filter Assignment, Example 2: Show MAB Configuration

Page 105 highlights

Example 2: Show MAB Configuration To show the MAB configuration for interface 1/5, use the following command: console#show dot1x ethernet 1/g5 Administrative Mode Enabled Port ------1/g5 Admin Mode mac-based Oper Mode -----------Authorized Reauth Control -------TRUE Reauth Period ---------300 Quiet Period 60 Transmit Period 30 Maximum Requests 2 Max Users 16 Supplicant Timeout 30 Server Timeout (secs 30 MAB mode (configured Enabled MAB mode (operational Enabled Logical Port ------64 Supplicant MAC-Address 0012.43D1.D19F AuthPAE State -----------Authenticated Backend State ----------- Idle VLAN Username Filter Id Id 1 Authentication Server Filter Assignment The PowerConnect M6220/M6348/M8024 switches allow the external 802.1X Authenticator or RADIUS server to assign DiffServ policies to users that authenticate to the switch. When a host (supplicant) attempts to connect to the network through a port, the switch contacts the 802.1X authenticator or RADIUS server, which then provides information to the switch about which DiffServ policy to assign the host (supplicant). The application of the policy is applied to the host after the authentication process has completed. To enable filter assignment by an external server, the following conditions must be true: 1 The port that the host is connected to must be enabled for MAC-based port access control by using the following command in Interface Config mode: dot1x port-control mac-based 2 The RADIUS or 802.1X server must specify the policy to assign. For example, if the DiffServ policy to assign is named internet_access, include the following attribute in the RADIUS or 802.1X server configuration: Device Security 105

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158

Device Security
105
Example 2: Show MAB Configuration
To show the MAB configuration for interface 1/5, use the following command:
console#show dot1x ethernet 1/g5
Administrative Mode
...............
Enabled
Port
Admin
Oper
Reauth
Reauth
Mode
Mode
Control
Period
-------
------------------
------------
--------
----------
1/g5
mac-based
Authorized
TRUE
300
Quiet Period
...................................
60
Transmit Period
................................
30
Maximum Requests
...............................
2
Max Users
......................................
16
Supplicant Timeout
.............................
30
Server Timeout (secs)
..........................
30
MAB mode (configured)
..........................
Enabled
MAB mode (operational)
.........................
Enabled
Logical
Supplicant
AuthPAE
Backend
VLAN
Username
Filter
Port
MAC-Address
State
State
Id
Id
-------
-----------------
------------
-----------
----- --------
--------
64
0012.43D1.D19F
Authenticated
Idle
1
Authentication Server Filter Assignment
The
PowerConnect M6220/M6348/M8024
switches
allow the external 802.1X Authenticator or RADIUS
server to assign DiffServ policies to users that authenticate to the switch. When a host (supplicant)
attempts to connect to the network through a port, the switch contacts the 802.1X authenticator or
RADIUS server, which then provides information to the switch about which DiffServ policy to assign the
host (supplicant). The application of the policy is applied to the host after the authentication process has
completed.
To enable filter assignment by an external server, the following conditions must be true:
1
The port that the host is connected to must be enabled for MAC-based port access control by using
the following command in Interface Config mode:
dot1x port-control mac-based
2
The RADIUS or 802.1X server must specify the policy to assign.
For example, if the DiffServ policy to assign is named internet_access, include the following attribute
in the RADIUS or 802.1X server configuration: