PowerConnect B-Series FCX Configuration Guide 127753-1002266-01Using multi-device port authentication and 802.1X security on the same port 36Configuring Dell-specific attributes on theRADIUS serverIf the RADIUS authentication process is successful, the RADIUS server sends an Access-Acceptmessage to the Dell PowerConnect device, authenticating the device. The Access-Accept messagecan include Vendor-Specific Attributes (VSAs) that specify additional information about the device.If you are configuring multi-device port authentication and 802.1X authentication on the sameport, then you can configure the Dell VSAs listed in Table 225 on the RADIUS server.You add these Dell vendor-specific attributes to your RADIUS server configuration, and configurethe attributes in the individual or group profiles of the devices that will be authenticated. The DellVendor-ID is 1991, with Vendor-Type 1.If neither of these VSAs exist in a device profile on the RADIUS server, then by default the device issubject to multi-device port authentication (if configured), then 802.1X authentication (ifconfigured). The RADIUS record can be used for both multi-device port authentication and 802.1Xauthentication.Configuration examples are shown in “Examples of multi-device port authentication and 802.1Xauthentication configuration on the same port” on page 1302.TABLE 225 Dell vendor-specific attributes for RADIUSAttribute name Attribute ID Data type DescriptionFoundry-802_1x-enable 6 integer Specifies whether 802.1X authentication isperformed when multi-device portauthentication is successful for a device. Thisattribute can be set to one of the following:0 - Do not perform 802.1X authentication ona device that passes multi-device portauthentication. Set the attribute to zero fordevices that do not support 802.1Xauthentication.1 - Perform 802.1X authentication when adevice passes multi-device portauthentication. Set the attribute to one fordevices that support 802.1X authentication.Foundry-802_1x-valid 7 integer Specifies whether the RADIUS record is validonly for multi-device port authentication, orfor both multi-device port authentication and802.1X authentication.This attribute can be set to one of thefollowing:0 - The RADIUS record is valid only formulti-device port authentication. Set thisattribute to zero to prevent a user from usingtheir MAC address as username andpassword for 802.1X authentication1 - The RADIUS record is valid for bothmulti-device port authentication and 802.1Xauthentication.