Configuring FastIron-specific attributes on the RADIUS server

If the RADIUS authentication process is successful, the RADIUS server sends an Access-Accept message to the FastIron device, authenticating the device. The Access-Accept message can include attributes that specify additional information about the device. If you are configuring MAC authentication and 802.1X authentication on the same port, you can configure the attributes listed in the following table on the RADIUS server.

You add the attributes to your RADIUS server configuration, and configure the attributes in the individual or group profiles of the devices that will be authenticated. The FastIron Vendor-ID is 1991, with Vendor-Type 1. For more information, refer to Configuring RADIUS.

Attributes for RADIUS

Attribute name

Attribute ID

Data type

Description

Foundry-802_1x-enable

6

integer

Specifies whether 802.1X authentication is performed when MAC authentication is successful for a device. This attribute can be set to one of the following:

0 - Do not perform 802.1X authentication on a device that passes MAC authentication. Set the attribute to 0 for devices that do not support 802.1X authentication.

1 - Perform 802.1X authentication when a device passes MAC authentication. Set the attribute to 1 for devices that support 802.1X authentication.

Foundry-802_1x-valid

7

integer

Specifies whether the RADIUS record is valid only for MAC authentication, or for both MAC authentication and 802.1X authentication.

This attribute can be set to one of the following:

0 - The RADIUS record is valid only for MAC authentication. Set this attribute to 0 to prevent a user from using their MAC address as the username and password for 802.1X authentication

1 - The RADIUS record is valid for both MAC authentication and 802.1X authentication.

These attributes can be used in a device profile on the RADIUS server for MAC authentication. These attributes are optional. They are only applicable when both MAC authentication and 802.1X authentication are configured on the port and the authentication sequence is MAC authentication followed by 802.1X authentication. These attributes are not needed in the device profile if only MAC authentication is enabled on the port.