Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessHard
A network security administrator is configuring a Cisco Catalyst switch to enforce secure network access using 802.1X. The requirement is for the switch to dynamically assign an endpoint to a specific VLAN based on the user's group membership in Active Directory, as determined by a RADIUS server. Which RADIUS attribute is primarily used by the Authentication Server to communicate the dynamic VLAN assignment to the switch?
- ANAS-Port-Id
- BFramed-IP-Address
- CService-Type
- DTunnel-Private-Group-ID
Show answer & explanationAnswer & explanation
Correct answer: D. Tunnel-Private-Group-ID
The RADIUS attribute `Tunnel-Private-Group-ID` (Attribute 81) is commonly used by the Authentication Server (e.g., Cisco ISE) to communicate the VLAN ID to the network access device (Authenticator/switch) for dynamic VLAN assignment in an 802.1X deployment.
Why the other options are wrong
- A. `NAS-Port-Id` (Attribute 5) identifies the physical port on the Network Access Server (NAS) where the user is connected, not used for dynamic VLAN assignment.
- B. `Framed-IP-Address` (Attribute 8) is used to assign an IP address to the user, not for VLAN assignment.
- C. `Service-Type` (Attribute 6) indicates the type of service being requested (e.g., login, framed-user) and is typically sent by the NAS, not for dynamic VLAN assignment.
RADIUS Tunnel-Private-Group-ID
The RADIUS `Tunnel-Private-Group-ID` attribute (Attribute 81) is used by an Authentication Server to dynamically assign a client to a specific VLAN during 802.1X authentication.
- Standard RADIUS attribute (Attribute 81).
- Carries the VLAN ID or name.
- Sent in an Access-Accept message from the RADIUS server.
- Received by the Authenticator (switch) to place the client in the specified VLAN.
Memory trick: Tunnel-Private-Group-ID is the 'VLAN Express Ticket'.