HP 5120 SI Series Security Configuration Manual page 81

Hide thumbs Also See for 5120 SI Series:
Table of Contents

Advertisement

Authentication status
A user in the critical VLAN
passes 802.1X
authentication.
A user in the 802.1X guest
VLAN or the Auth-Fail VLAN
fails authentication because
all the RADIUS servers is
reachable.
2.
On a port that performs MAC-based access control
Authentication status
A user that has not been
assigned to any VLAN fails
802.1X authentication
because all the RADIUS
servers are unreachable.
A user in the 802.1X critical
VLAN fails authentication
because all the RADIUS
servers are unreachable.
A user in the critical VLAN
fails 802.1X authentication for
any other reason than server
unreachable.
A user in the critical VLAN
passes 802.1X
authentication.
A user in the 802.1X guest
VLAN or the Auth-Fail VLAN
fails authentication because
all the RADIUS server are
unreachable.
A user in the MAC
authentication guest VLAN
fails 802.1X authentication
because all the 802.1X
authentication server are
unreachable.
VLAN manipulation
Assigns the VLAN specified for the user to the port as the PVID, and
removes the port from the critical VLAN. After the user logs off, the default
or user-configured PVID restores.
If the authentication server assigns no VLAN, the default or user-configured
PVID applies. The user and all subsequent 802.1X users are assigned to this
port VLAN. After the user logs off, this PVID remains unchanged.
The PVID of the port remains unchanged. All 802.1X users on this port can
access only resources in the guest VLAN or the Auth-Fail VLAN.
VLAN manipulation
Maps the MAC address of the user to the critical VLAN. The user can access
only resources in the critical VLAN.
The user is still in the critical VLAN.
If an Auth-Fail VLAN has been configured, re-maps the MAC address of the
user to the Auth-Fail VLAN ID.
Re-maps the MAC address of the user to the server-assigned VLAN.
If the authentication server assigns no VLAN, re-maps the MAC address of the
user to the default or user-configured PVID on the port.
The user remains in the 802.1X VLAN or the Auth-Fail VLAN.
The user is removed from the MAC authentication VLAN and mapped to the
802.1X critical VLAN.
69

Advertisement

Table of Contents
loading

Table of Contents