Configuring An 802.1X Critical Vlan; Configuration Guidelines; Configuration Prerequisites; Configuration Procedure - HP 6125G Configuration Manual

Security configuration guide
Hide thumbs Also See for 6125G:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Enter Ethernet interface view.
3.
Configure the Auth-Fail VLAN
on the port.

Configuring an 802.1X critical VLAN

Configuration guidelines

Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X critical VLAN on a port, so
the port can correctly process VLAN tagged incoming traffic.
You can configure only one 802.1X critical VLAN on a port. The 802.1X critical VLANs on different
ports can be different.
When the port moves between VLANs (for example, leaves the 802.1X guest VLAN and joins the
critical VLAN), ask 802.1X users to manually update their IP address so that they can access
specific resources.

Configuration prerequisites

Create the VLAN to be specified as a critical VLAN.
If the 802.1X-enabled port performs port-based access control, enable 802.1X multicast trigger
(dot1x multicast-trigger).
If the 802.1X-enabled port performs MAC-based access control, configure the port as a hybrid port,
enable MAC-based VLAN on the port, and assign the port to the Auth-Fail VLAN as an untagged
member. For more information about the MAC-based VLAN function, see Layer 2
Configuration Guide.

Configuration procedure

To configure an 802.1X critical VLAN:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Configure an 802.1X critical
VLAN on the port.
4.
Configure the port to trigger
802.1X authentication on
detection of a reachable
authentication server for users
in the critical VLAN.
Command
system-view
interface interface-type
interface-number
dot1x auth-fail vlan authfail-vlan-id
Command
system-view
interface interface-type
interface-number
dot1x critical vlan vlan-id
dot1x critical recovery-action
reinitialize
89
Remarks
N/A
N/A
By default, no Auth-Fail VLAN is
configured.
LAN Switching
Remarks
N/A
N/A
By default, no critical VLAN is
configured.
Optional.
By default, when a reachable
RADIUS server is detected, the
system removes the port or 802.1X
users from the critical VLAN
without triggering authentication.

Advertisement

Table of Contents
loading

This manual is also suitable for:

6125 blade switch series

Table of Contents