Support For Guest Vlan And Auth-Fail Vlan - HP 5120 SI Series Security Configuration Manual

Hide thumbs Also See for 5120 SI Series:
Table of Contents

Advertisement

This mode is similar to the userLoginSecure mode except that this mode supports multiple online 802.1X
users.
4.
userLoginWithOUI
This mode is similar to the userLoginSecure mode. The difference is that a port in this mode also permits
frames from one user whose MAC address contains a specified organizationally unique identifier (OUI).
For wired users, the port performs 802.1X authentication upon receiving 802.1X frames, and performs
OUI check upon receiving non-802.1X frames.
Perform MAC authentication
macAddressWithRadius: A port in this mode performs MAC authentication and services multiple users.
Perform a combination of MAC authentication and 802.1X authentication
1.
macAddressOrUserLoginSecure
This mode is the combination of the macAddressWithRadius and userLoginSecure modes.
For wired users, the port performs MAC authentication upon receiving non-802.1X frames and performs
802.1X authentication upon receiving 802.1X frames.
2.
macAddressOrUserLoginSecureExt
This mode is similar to the macAddressOrUserLoginSecure mode except that a port in this mode supports
multiple 802.1X and MAC authentication users.
3.
macAddressElseUserLoginSecure
This mode is the combination of the macAddressWithRadius and userLoginSecure modes, with MAC
authentication having a higher priority as the Else keyword implies.
For non-802.1X frames, a port in this mode performs only MAC authentication. For 802.1X frames, it
performs MAC authentication and then, if the authentication fails, 802.1X authentication.
4.
macAddressElseUserLoginSecureExt
This mode is similar to the macAddressElseUserLoginSecure mode except that a port in this mode
supports multiple 802.1X and MAC authentication users as the keyword Ext implies.
NOTE:
The maximum number of users a port supports equals the maximum number of secure MAC addresses
or the maximum number of authenticated users the security mode supports, whichever is smaller.
For more information about configuring MAC address table entries, see the
Command Reference

Support for guest VLAN and Auth-Fail VLAN

An 802.1X guest VLAN is the VLAN that a user is in before initiating authentication. An 802.1X Auth-Fail
VLAN or a MAC authentication guest VLAN is the VLAN that a user is in after failing authentication.
Support for the guest VLAN and Auth-Fail VLAN features varies with security modes.
You can use the 802.1X guest VLAN and 802.1X Auth-Fail VLAN features together with port security
modes that support 802.1X authentication. For more information about the 802.1X guest VLAN and
Auth-Fail VLAN on a port that performs MAC-based access control, see the chapter "802.1X
configuration."
.
174
Layer 2—LAN Switching

Advertisement

Table of Contents
loading

Table of Contents