HP FlexFabric 5700 Series Security Configuration Manual page 115

Hide thumbs Also See for FlexFabric 5700 Series:
Table of Contents

Advertisement

Table 10
shows the way that the network access device handles guest VLANs for MAC authentication
users.
Table 10 VLAN manipulation
Authentication status
A user in the MAC authentication
guest VLAN fails MAC
authentication for any other
reason than server unreachable.
A user in the MAC authentication
guest VLAN passes MAC
authentication.
Critical VLAN
You can configure a MAC authentication critical VLAN on a port to accommodate users that fail MAC
authentication because no RADIUS authentication server is reachable. Users in a MAC authentication
critical VLAN can access only network resources in the critical VLAN.
The critical VLAN feature takes effect when MAC authentication is performed only through RADIUS
servers. If a MAC authentication user fails local authentication after RADIUS authentication, the user is
not assigned to the critical VLAN. For more information about the authentication methods, see
"Configuring
Table 1 1
shows the way that the network access device handles critical VLANs for MAC authentication
users.
Table 11 VLAN manipulation
Authentication status
A user that has not been assigned to any VLAN
fails MAC authentication because all the
RADIUS servers are unreachable.
A user in the MAC authentication critical VLAN
fails MAC authentication for any other reason
than server unreachable.
A user in the MAC authentication critical VLAN
passes MAC authentication.
VLAN manipulation
The user is still in the MAC authentication guest VLAN.
The device remaps the MAC address of the user to the authorization VLAN
assigned by the authentication server.
If no authorization VLAN is configured for the user on the authentication
server, the device remaps the MAC address of the user to the PVID of the
port.
AAA."
VLAN manipulation
The device maps the MAC address of the user to the MAC
authentication critical VLAN.
The user is still in the MAC authentication critical VLAN if
the user fails MAC reauthentication because all the RADIUS
servers are unreachable.
If a guest VLAN has been configured, the device maps the
MAC address of the user to the guest VLAN.
If no guest VLAN is configured, the device remaps the MAC
address of the user to the PVID of the port.
The device remaps the MAC address of the user to the
authorization VLAN assigned by the authentication server.
If no authorization VLAN is configured for the user on the
authentication server, the device remaps the MAC address
of the user to the PVID of the access port.
103

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents