To aid the proper authentication attributes sent from the RADIUS server to the device, several vendor-specific attributes (VSAs) exist to provide client-specific information from the device and information received from the Fabric Attach client at the time it connects to the network.
ExtremeXOS 31.1 introduces support in Fabric Attach for the following VSAs. Attributes are sent only for NetLogin MAC- and Dot1x-based authentications.
VSA | Vendor Type | Description |
---|---|---|
Switch Mode (FA-Switch-Mode) | 180 | Defines the configuration of the FA device itself. It can take on 6
different values.
|
Client Identifer (FA-Client-ID) | 181 | Contains the MAC address of the FA Client received from the FA LLDP messaging. |
Client Type (FA-Client-Type) | 182 | Informs the RADIUS server of what the user requesting
authentication‘s primary purpose is. This can allow the RADIUS server to
return a consistent set of attributes for clients who have a similar
purpose. Accepted values are in the range of 6–17 (client types, not
server or proxy types) for this attribute, though values 1–17 are
defined.
|
Pre-shared Key (PSK) Status (FA-Client-PSK) | 183 | Used to inform the RADIUS server of the Pre-shared Key status of the
client being authenticated. If sent, it can take one of 5 binary values,
0,10,11,100,101.
|
ExtremeSwitching X435, X450-G2, X460-G2, X670-G2, X440-G2, X465, X590, X620, X690, X695, X870, and 5520 series switches.