Michael Roberts
Guest
|
Posted:
Thu Nov 11, 2004 6:42 am Post subject:
Re: Radius VSAs for Baystack 5510 & BPS2k |
|
|
Michael Roberts wrote:
| Quote: | I recently posted a message to this group looking for vendor specific
Radius attributes for dynamic VLAN assignments through 802.1x EAPoL.
Through my Nortel SE, Google, and Nortel tech support, I have found some
excellent information.
|
Grrrr.. Darn Thunderbird reader, posted before I was ready...
Anyway, the following the three specific attributes needed.
• Tunnel-Type = 13 (sets the Tunnel-Type to VLAN)
• Tunnel-Medium-Type = 6 (sets the Tunnel-Medium-Type to 802)
• Tunnel-Private-Group-Id = <VLAN ID> (set the VLAN ID for the user)
The switch must have Auto-PVID enabled and be using port based VLANs.
If you are using Freeradius, these attributes are already defined in
existing dictionaries, so there is no need to write your own Nortel
dictionary unless you plan on using Nortel specific VSAs. Still working
out all of the details, but I have this working. If anyone wants more
specific details, shoot me a note offline.
-mike |
|