918 BigIron RX Series Configuration Guide53-1001986-01How multi-device port authentication works31Authentication-failure actionsIf the MAC address does not match the username and password of an entry in the users databaseon the RADIUS server, then the RADIUS server returns an Access-Reject message. When thishappens, it is considered an authentication failure for the MAC address. When an authenticationfailure occurs, the device can either drop traffic from the MAC address in hardware (the default), ormove the port on which the traffic was received to a restricted VLAN.BigIron RX Series support multi-device port authentication on untagged ports only.Supported RADIUS attributesThe BigIron RX supports the following RADIUS attributes for multi-device port authentication:• Username (1) – RFC 2865• FilterId (11) – RFC 2865• Vendor-Specific Attributes (26) – RFC 2865• Tunnel-Type (64) – RFC 2868• Tunnel-Medium-Type (65) – RFC 2868• EAP Message (79) – RFC 2579• Tunnel-Private-Group-Id (81) – RFC 2868Dynamic VLAN and ACL assignmentsThe multi-device port authentication feature supports dynamic VLAN assignment, where a port canbe placed in a VLAN based on the MAC address learned on that interface. When a MAC address issuccessfully authenticated, the RADIUS server sends the device a RADIUS Access-Accept messagethat allows the device to forward traffic from that MAC address. The RADIUS Access-Acceptmessage can also contain attributes set for the MAC address in its access profile on the RADIUSserver.If one of the attributes in the Access-Accept message specifies a VLAN identifier, and this VLAN isavailable on the device, the port is moved from its default VLAN to the specified VLAN.To enable dynamic VLAN assignment for authenticated MAC addresses, you must add the followingattributes to the profile for the MAC address on the RADIUS server. Dynamic VLAN assignment onmulti-device port authentication-enabled interfaces is enabled by default.In addition to dynamic VLAN assignment, BigIron RX Series also support dynamic ACL assignmentas is the case with 802.1x port security.Attribute name Type ValueTunnel-Type 064 13 (decimal) – VLANTunnel-Medium-Type 065 6 (decimal) – 802Tunnel-Private-Group-ID 081 (string) – either the name or the number of aVLAN configured on the device.