Configuring An 802.1X Guest Vlan; Configuring An Auth-Fail Vlan - HP 1910 User Manual

Hide thumbs Also See for 1910:
Table of Contents

Advertisement

Item
Enable Handshake
Enable Re-Authentication
Guest VLAN
Auth-Fail VLAN

Configuring an 802.1X guest VLAN

Configuration prerequisites
Create the VLAN to be specified as the 802.1X guest VLAN.
On the 802.1X-enabled port that performs port-based access control, enable 802.1X multicast
trigger at the command line interface. (802.1X multicast trigger is enabled by default.)
Configuration guidelines
You can configure only one 802.1X guest VLAN on a port. The 802.1X guest VLANs on different
ports can be different.
Assign different IDs to the voice VLAN, the PVID, and the 802.1X guest VLAN on a port, so the port
can correctly process incoming VLAN tagged traffic.
With 802.1X authentication, a hybrid port is always assigned to a VLAN as an untagged member.
After the assignment, do not re-configure the port as a tagged member in the VLAN.

Configuring an Auth-Fail VLAN

Configuration prerequisites
Create the VLAN to be specified as the 802.1X Auth-Fail VLAN.
On the 802.1X-enabled port that performs port-based access control, enable 802.1X multicast
trigger. (802.1X multicast trigger is enabled by default.)
Configuration guidelines
Assign different IDs to the voice VLAN, PVID and the 802.1X Auth-Fail VLAN on a port, so the port can
correctly process VLAN tagged incoming traffic.
Description
Select the box to enable the online user handshake function.
The online user handshake function checks the connectivity status of online
802.1X users. The network access device sends handshake messages to online
users at the interval specified by the Handshake Period option. If no response is
received from an online user after the maximum number of handshake attempts
(set by the Retry Times option) has been made, the network access device sets the
user in the offline state. For information about the timers, see
Select the box to enable periodic online user re-authentication on the port.
Periodic online user re-authentication tracks the connection status of online users
and updates the authorization attributes assigned by the server, such as the ACL,
and VLAN. The re-authentication interval is specified by the Re-Authentication
Period option in
Table
105.
Specify an existing VLAN as the guest VLAN. For more information, see
"Configuring an 802.1X guest
Specify an existing VLAN as the Auth-Fail VLAN to accommodate users that have
failed 802.1X authentication.
For more information, see
317
VLAN."
"Configuring an Auth-Fail
Table
105.
VLAN."

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents