Security Modes For Vmps Server - Cisco Catalyst 4500 Series Configuration Manual

Release ios xe 3.3.0sg and ios 15.1(1)sg
Hide thumbs Also See for Catalyst 4500 Series:
Table of Contents

Advertisement

VLAN Membership Policy Server

Security Modes for VMPS Server

VMPS operates in three different modes. The way a VMPS server responds to illegal requests depends
on the mode in which the VMPS is configured:
Open Mode
If no VLAN is assigned to this port, VMPS verifies the requesting MAC address against this port:
If a VLAN is already assigned to this port, VMPS verifies the requesting MAC address against this port:
Secure Mode
If no VLAN is assigned to this port, VMPS verifies the requesting MAC address against this port:
If a VLAN is already assigned to this port, VMPS verifies the requesting MAC address against this port:
Multiple Mode
Multiple hosts (MAC addresses) can be active on a dynamic port if they are all in the same VLAN. If the
link fails on a dynamic port, the port returns to the unassigned state. Any hosts that come online through
the port are checked again with VMPS before the port is assigned to a VLAN.
If multiple hosts connected to a dynamic port belong to different VLANs, the VLAN matching the MAC
address in the last request is returned to the client provided that multiple mode is configured on the
VMPS server.
Note
Although Catalyst 4500 series and Catalyst 6500 series switches running Catalyst operating system
software support VMPS in all three operation modes, the User Registration Tool (URT) supports open
mode only.
Software Configuration Guide—Release IOS XE 3.3.0SG and IOS 15.1(1)SG
15-22
Open Mode, page 15-22
Secure Mode, page 15-22
Multiple Mode, page 15-22
If the VLAN associated with this MAC address is allowed on the port, the VLAN name is returned
to the client.
If the VLAN associated with this MAC address is not allowed on the port, the host receives an
"access denied" response.
If the VLAN associated with this MAC address in the database does not match the current VLAN
assigned on the port, and a fallback VLAN name is configured, VMPS sends the fallback VLAN
name to the client.
If a VLAN associated with this MAC address in the database does not match the current VLAN
assigned on the port, and a fallback VLAN name is not configured, the host receives an "access
denied" response.
If the VLAN associated with this MAC address is allowed on the port, the VLAN name is returned
to the client.
If the VLAN associated with this MAC address is not allowed on the port, the port is shut down.
If a VLAN associated with this MAC address in the database does not match the current VLAN
assigned on the port, the port is shutdown, even if a fallback VLAN name is configured.
Chapter 15
Configuring VLANs, VTP, and VMPS
OL-25340-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents