Setup Guide
Verify RADIUS attribute conguration
Verify the attribute conguration using the show running-config command.
DellEMC# show running-config
!
radius-server host 10.16.206.77 key 7 387a7f2df5969da4
radius-server attribute 8 include-in-access-req
radius-server attribute 168 include-in-access-req
!
dot1x authentication
!
RADIUS-assigned dynamic access control lists
Dell EMC Networking OS supports RADIUS-assigned dynamic access control lists (DACLs) to control the trac from authenticated
supplicant.
RADIUS-assigned DACLs control Layer 3 (L3) trac from a supplicant authenticated by the RADIUS server using 802.1x/MAC
Authentication Bypass (MAB). The RADIUS server pushes the DACLs to an OS9 switch that acts as network access server (NAS). Dell
EMC Networking OS applies the downloaded DACLs to an interface or a specic supplicant session(s)/ user(s) in the interface. OS9
switch uses RADIUS-assigned DACLs to lter L3 trac entering the switch from authenticated supplicant(s) which has RADIUS-assigned
DACL congured in the RADIUS server. This feature allows a centralized administration of security policies for access devices in enterprises
without the need of handling the access policies in the individual devices.
Standard compliance
Dell EMC Networking OS complies to the following standards:
• RFC4849 for RADIUS NAS-Filter-Rule attribute
• RFC2865 For Filter-Id attribute
Conguration notes
Consider the following when conguring RADIUS-assigned DACL in the switch:
• RADIUS-assigned DACLs are applicable only for the inbound trac on a specic port of the switch or supplicant.
• NAS supports unique session based on RADIUS-assigned DACLs using the MAC address of the 802.1x client.
• RADIUS-assigned DACLs and ACLs congured through the OS9 CLI can coexist. RADIUS-assigned DACLs takes higher precedence
over the L3 ACL congured using OS9 CLI.
• IPv6 NAS-Filter-Rule attributes are not supported as part of Radius-assigned DACLs.
• Change of Authorization (CoA) Action requests on the RADIUS NAS-Filter-Rule Attributes are not supported.
• The attributes in RADIUS NAS-Filter-Rule supports only the L3 options.
• The RADIUS-assigned DACLs are implicit permit. You can congure an implicit deny rule deny ip any any explicitly to block all
other trac.
• The maximum size of the RADIUS-assigned DACLs through NAS-Filter-Rule attribute is 4000 characters. It can be a single rule or
multiple rules.
• The names of ACLs congured using the OS9 CLI must be dierent from the name of the RADIUS-assigned DACLs downloaded from
the RADIUS server.
• After switch failover, you must do the following on the interface before changing any dot1x related congurations:
a Shutdown the interface using shutdown command
Security
793