Non-Supplicant Policy Examples - Alcatel-Lucent OmniSwitch 6800 Series Network Configuration Manual

Hide thumbs Also See for OmniSwitch 6800 Series:
Table of Contents

Advertisement

Configuring Access Guardian Policies

Non-supplicant Policy Examples

The following table provides example non-supplicant policy commands and a description of how the
resulting policy is applied to classify supplicant devices:
Supplicant Policy Command Example
802.1x 1/24 non-supplicant policy authentication
pass group-mobility default-vlan fail vlan 10 block
802.1x 1/48 non-supplicant policy authentication
vlan 10 default-vlan
802.1x 2/1 non-supplicant policy authentication
fail vlan 100 default-vlan
page 27-18
Description
If the MAC authentication process is successful
but does not return a VLAN ID for the device, then
the following occurs:
1
2
If the device fails MAC authentication, then the
following occurs:
1
2
If the MAC authentication process is successful
but does not return a VLAN ID for the device, then
the following occurs:
1
2
If the device fails MAC authentication, the device
is blocked from accessing the switch on port 1/48.
If MAC authentication does not return a VLAN
ID, the device is blocked from accessing the switch
on port 2/1.
If the device fails MAC authentication, then the
following occurs:
1
2
3
OmniSwitch 6800/6850/9000 Network Configuration Guide
Group Mobility rules are applied.
If Group Mobility classification fails, then the
device is assigned to the default VLAN for
port 1/24.
If VLAN 10 exists and is not an authenticated
VLAN, the device is assigned to VLAN 10.
If VLAN 10 does not exist or is an authenti-
cated VLAN, the device is blocked from
accessing the switch on port 1/24.
The device is assigned to VLAN 10.
If VLAN 10 does not exist, then the device is
assigned to the default VLAN for port 1/48.
If VLAN 100 exists and is not an authenti-
cated VLAN, the device is assigned to VLAN
100.
If VLAN 100 does not exist or is an authenti-
cated VLAN, the device is assigned to the
default VLAN for port 2/1.
If the default VLAN for port 2/1 is an authenti-
cated VLAN, then the device is blocked from
accessing the switch on port 2/1.
Configuring 802.1X
March 2008

Advertisement

Table of Contents
loading

This manual is also suitable for:

Omniswitch 6850 seriesOmniswitch 9000 series

Table of Contents