Brocade-Ruckus-Arris Wired Layer 2 Integration

Note – In this example, a Brocade/Ruckus/Arris ICX 7450 configuration is provided. However, any ICX Layer 2 switch supporting the following features are eligible for integration. Impulse recommends version 8.0.30 or later.

  • RADIUS Authentication/Accounting
  • 802.1X / MAC Authentication
  • RADIUS Change of Authorization (CoA)
  • Dynamic VLAN Assignment

Note – In this example the NAC RADIUS Server / Policy Server is 10.10.10.10 (replace this IP with the IP of your NAC system). Also replace the auth-default-vlan and test port numbers with desired values.

Bash
Copy

Note – For VOIP environments ensure LLDP is enabled, LLDP pass-through is enabled under authentication and no voice VLAN is configured on the test port.

Bash
Copy

Note – For VOIP environments, the NAC RADIUS server must be configured to return the following RADIUS attributes. This will ensure the voice vlan is returned and also ensure the phone does not attempt 802.1X authentication as mac authentication will have already occurred.

Bash
Copy
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard