H3C S7500 Series Ethernet Switches Command Manual

Table Of Contents
Command Manual – AAA & RADIUS & HWTACACS & EAD
H3C S7500 Series Ethernet Switches
Chapter 1 AAA & RADIUS & HWTACACS
Configuration Commands
1-22
By default, the VLAN assignment mode is integer; that is, the switch supports its
RADIUS authentication server to assign integer VLAN IDs.
The dynamic VLAN assignment feature enables a switch to dynamically add the ports
with successfully authenticated users to different VLANs according to the attributes
assigned by the RADIUS server, so as to control the network resources that different
users can access. In actual applications, to use this feature together with Guest VLAN,
you should better set port control to port-based mode.
Currently, the switch supports the RADIUS authentication server to assign the following
two types of VLAN IDs: integer and string.
z Integer: Upon receiving an integer ID assigned by the RADIUS authentication
server, the switch adds the port to the VLAN whose VLAN ID is equal to the
assigned integer ID. If no such a VLAN exists, the switch first creates a VLAN with
the assigned ID, and then adds the port to the newly created VLAN.
z String: Upon receiving a string ID assigned by the RADIUS authentication server,
the switch compares the ID with existing VLAN names on the switch. If it finds a
match, it adds the port to the corresponding VLAN. Otherwise, the VLAN
assignment fails and the user cannot pass the authentication.
The two dynamic VLAN assignment modes, integer and string, supported by the switch
are set according to the authentication server. Different authentication servers adopt
different dynamic VLAN assignment modes, you are recommended to configure the
device according to the dynamic VLAN assignment mode in use.
Table 1-3 lists some common dynamic VLAN assignment modes.
Table 1-3 Common dynamic VLAN assignment modes
Server type Dynamic VLAN assignment mode
CAMS
Integer (the mode of the latest version is
determined by the attribute)
ACS String
FreeRADIUS
Determined by the attribute (100 for
integer; “100” for string)
Shiva Access Manager String
Steel-Belted Radius Administrator String