Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessHard

A network security administrator is configuring a Cisco Catalyst switch to enforce secure network access using 802.1X. The requirement is for the switch to dynamically assign an endpoint to a specific VLAN based on the user's group membership in Active Directory, as determined by a RADIUS server. Which RADIUS attribute is primarily used by the Authentication Server to communicate the dynamic VLAN assignment to the switch?

  1. ANAS-Port-Id
  2. BFramed-IP-Address
  3. CService-Type
  4. DTunnel-Private-Group-ID
Show answer & explanation

Correct answer: D. Tunnel-Private-Group-ID

The RADIUS attribute `Tunnel-Private-Group-ID` (Attribute 81) is commonly used by the Authentication Server (e.g., Cisco ISE) to communicate the VLAN ID to the network access device (Authenticator/switch) for dynamic VLAN assignment in an 802.1X deployment.

Why the other options are wrong

  • A. `NAS-Port-Id` (Attribute 5) identifies the physical port on the Network Access Server (NAS) where the user is connected, not used for dynamic VLAN assignment.
  • B. `Framed-IP-Address` (Attribute 8) is used to assign an IP address to the user, not for VLAN assignment.
  • C. `Service-Type` (Attribute 6) indicates the type of service being requested (e.g., login, framed-user) and is typically sent by the NAS, not for dynamic VLAN assignment.

RADIUS Tunnel-Private-Group-ID

The RADIUS `Tunnel-Private-Group-ID` attribute (Attribute 81) is used by an Authentication Server to dynamically assign a client to a specific VLAN during 802.1X authentication.

  • Standard RADIUS attribute (Attribute 81).
  • Carries the VLAN ID or name.
  • Sent in an Access-Accept message from the RADIUS server.
  • Received by the Authenticator (switch) to place the client in the specified VLAN.

Memory trick: Tunnel-Private-Group-ID is the 'VLAN Express Ticket'.

More Endpoint Security and Secure Network Access questions