Configuring the RADIUS Server to Support Dynamic VLAN Assignment for Authentication
Dynamic VLAN assignments from the RADIUS server can be enabled in multiple formats. VLAN assignments can be tagged, untagged, single, multiple, or a combination of tagged and untagged VLANs for different use cases, for example, with client devices such as computers, IP phones, wireless access points, or servers running hypervisors that have multiple Virtual Machines (VMs).
To specify VLAN identifiers on the RADIUS server, add the attributes in the following table to the device (client) profile for MAC authentication. For 802.1X authentication, add these attributes to the user (client) profile.
Attributes for Dynamic VLAN Assignment
The ICX device interprets the attributes as follows:
- If the Tunnel-Type or the Tunnel-Medium-Type attributes in the Access-Accept message do not have the specified values, the ICX device ignores these Attribute-Value pairs. If the Tunnel-Private-Group-ID is valid, the client is authorized in this VLAN; otherwise, it is authorized in the auth-default VLAN.
- When the ICX device receives and parses the Tunnel-Private-Group-ID attribute, it checks whether the vlan-name string matches the name of a configured VLAN or the vlan-id on the ICX device. If there is a VLAN match, the client port is placed in the VLAN.
- If the vlan-name string does not match either the name or the ID of a VLAN configured on the ICX device, the VLAN name or ID is created and then used.
VLAN-Group Assignment
The Tunnel-Private-Group-ID also supports a single configured VLAN group. The VLAN-group ID on the RADIUS Server must be configured as G:< >, with or without an untagged VLAN.
The Tunnel-Private-Group-ID is supported for a vlan-group in the following formats:
- Tunnel-Private-Group-Id = “G:20”
- Tunnel-Private-Group-Id = “U:200;G:20”
- Tunnel-Private-Group-Id = “G:20; U:200”
The ICX device interprets the attributes as follows:
- If the Tunnel-Type or the Tunnel-Medium-Type attributes in the Access-Accept message do not have the specified values, authentication fails, and the ICX device generates a syslog message.
- If the Tunnel-Private-Group-ID is valid, the authenticated port is added as a tagged member of the VLANs that are part of the VLAN-group.
VLAN-Group Assignment Considerations
Keep the following points in mind when configuring dynamically assigned VLANs or VLAN groups.
- The VLAN group must already be configured
using the
vlan-groupcommand as shown in the following example. The configured VLAN group ID must be a value from 1 through 32. A maximum of 32 VLANs can be grouped under the same VLAN-group ID.device# configure terminal device(config)# vlan-group 20 vlan 5 to 10
- The Tunnel-Private-Group-id attribute supports only 32 VLANs.
- If the VLAN group is expected and not present, the ICX generates a syslog failure message.
- If the RADIUS server sends more than one VLAN group, authentication fails.
- If the RADIUS server sends a VLAN group and tagged VLANs in the attribute, authentication fails.
- ICX devices do not support DHCP snooping on VLAN groups.
- Any modification made to the VLAN group does not apply to a session that is already authenticated. Changes are applied when the session reauthenticates.
- The
show authentication session detailand theshow authentication session allcommands display VLAN IDs rather than the VLAN group ID.