Characteristics Of Mixed Port Access Mode - HP ProCurve 6120G/XG Manual

Hp procurve series 6120 blade switches access security guide
Hide thumbs Also See for ProCurve 6120G/XG:
Table of Contents

Advertisement

Configuring Port-Based and User-Based Access Control (802.1X)
Configuring Switch Ports as 802.1X Authenticators
when none of the authenticated clients are authorized on the untagged authen­
ticated VLAN. Instead of having just one client per port, multiple clients can
use the guest VLAN.
Authenticated clients always have precedence over guests (unauthenticated
clients) if access to a client's untagged VLAN requires removal of a guest VLAN
from the port. If an authenticated client becomes authorized on its untagged
VLAN as the result of initial authentication or because of an untagged packet
from the client, then all 802.1X or Web/MAC authenticated guests are removed
from the port and the port becomes an untagged member of the client's
untagged VLAN.

Characteristics of Mixed Port Access Mode

N o t e
If you disable mixed port access mode, this does not automatically remove
guests that have already been authorized on a port where an authenticated
client exists. New guests are not allowed after the change, but the existing
authorized guests will still be authorized on the port until they are removed
by a new authentication, an untagged authorization, a port state change, and
so on.
12-30
The port keeps tagged VLAN assignments continuously.
The port sends broadcast traffic from the VLANs even when there are only
guests authorized on the port.
Guests cannot be authorized on any tagged VLANs.
Guests can use the same bandwidth, rate limits and QoS settings that may
be assigned for authenticated clients on the port (via RADIUS attributes).
When no authenticated clients are authorized on the untagged authenti­
cated VLAN, the port becomes an untagged member of the guest VLAN
for as long as no untagged packets are received from any authenticated
clients on the port.
New guest authorizations are not allowed on the port if at least one
authenticated client is authorized on its untagged VLAN and the guest
VLAN is not the same as the authenticated client's untagged VLAN.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve 6120xgProcurve 6120 series

Table of Contents