Enterasys 802.1Q Spécifications Page 13

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 36
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 12
Authentication Overview
April 15, 2011 Page 13 of 36
authorizationisenabledgloballyandontheauthenticatingusersport,theVLANspecifiedby
thetunnelattributesisappliedtotheauthenticatinguser.
IfVLANauthorizationisnotenabled,theVLANspecifiedbythepolicyprofileisapplied.See
RFC3580onpage 10forinformationaboutVLANauthorization.
•Ifthe
FilterIDattribut esarepresentbutthetunnelattributesarenotpresent,thepolicy
profilespecifiedbytheFilterIDisapplied,alongwiththeVLANspecifiedbythepolicy
profile.
•IfthetunnelattributesarepresentbuttheFilterIDattributesarenotpresent,andifVLAN
authorizationisenabled
globallyandontheauthenticatingusersport,thentheswitchwill
checktheVLANtopolicymappingtable(configuredwiththesetpolicymaptable
command):
–IfanentrymappingthereceivedVLANIDtoapolicyprofileisfound,thenthatpolicy
profile,alongwiththeVLANspecifiedbythepolicy
profile,willbeappliedtothe
authenticatinguser.
–Ifnomatchingmappingtableentryisfound,theVLANspecifiedbythetunnelattributes
willbeappliedtotheauthenticatinguser.
–IftheVLANtopolicymappingtableisinvalid,thenthe
etsysPolicyRFC3580MapInvalidMappingMIBisincrementedandtheVLANspecifiedby
thetunnel
attributeswillbeappliedtotheauthenticatinguser.
IfVLANauthorizationisnotenabled,thetunnelattributesareignored.
When Policy Maptable Response is “Profile”
WhentheswitchisconfiguredtouseonlyFilterIDattributes,bysettingthesetpolicymaptable
commandresponseparametertopolicy:
•IftheFilterIDattributesarepresent,thespecifiedpolicyprofilewillbeappliedtothe
authenticatinguser.IfnoFilterIDattributesarepresent,thedefaultpolicy(if
itexists)willbe
applied.
•Ifthetunnelattributesarepresent,theyareignored.NoVLANtopolicymappingwilloccur.
When Policy Maptable Response is “Tunnel”
Whentheswitchisconfiguredtouseonlytunnelattributes,bysettingthesetpolicymaptable
commandresponseparametertotunnel,andifVLANauthorizationisenabledbothgloballyand
ontheauthenticatingusersport:
•Ifthetunnelattributesarepresent,the sp ecifiedVLANwillbeappliedtotheauthenticating
user.
VLANtopolicymappingcanoccuronamodularswitchplatform;VLANtopolicy
mappingwillnotoccuronastackablefixedswitchorstandalonefixedswitchplatform.
•Ifthetunnelattributesarenotpresent,thedefaultpolicyVLANwillbeapplied;ifthedefault
policyVLANisnotconfigured,the
portVLANwillbeapplied.
•IftheFilterIDattributesarepresent,theyareignored.
IfVLANauthorizationisnotenabled,theuserwillbeallowedontotheportwiththedefault
policy,ifitexists.Ifnodefaultpolicyexists,theportVLANwillbeapplied.
Vue de la page 12
1 2 ... 8 9 10 11 12 13 14 15 16 17 18 ... 35 36

Commentaires sur ces manuels

Pas de commentaire