Configuring Dynamic Vlan Assignment With Port Authentication - Dell S4820T Configuration Manual

Hide thumbs Also See for S4820T:
Table of Contents

Advertisement

The bold lines show the new supplicant and server timeouts.
Dell(conf-if-Te-1/1)#dot1x port-control force-authorized
Dell(conf-if-Te-1/1)#do show dot1x interface TenGigabitEthernet 1/1
802.1x information on Te 1/1:
-----------------------------
Dot1x Status:
Port Control:
Port Auth Status:
Re-Authentication:
Untagged VLAN id:
Guest VLAN:
Guest VLAN id:
Auth-Fail VLAN:
Auth-Fail VLAN id:
Auth-Fail Max-Attempts:
Tx Period:
Quiet Period:
ReAuth Max:
Supplicant Timeout:
Server Timeout:
Re-Auth Interval:
Max-EAP-Req:
Auth Type:
Auth PAE State:
Backend State:
Enter the tasks the user should do after finishing this task (optional).
Configuring Dynamic VLAN Assignment with Port
Authentication
Dell Networking OS supports dynamic VLAN assignment when using 802.1X.
The basis for VLAN assignment is RADIUS attribute 81, Tunnel-Private-Group-ID. Dynamic VLAN
assignment uses the standard dot1x procedure:
1.
The host sends a dot1x packet to the Dell Networking system
2.
The system forwards a RADIUS REQEST packet containing the host MAC address and ingress port
number
3.
The RADIUS server authenticates the request and returns a RADIUS ACCEPT message with the VLAN
assignment using Tunnel-Private-Group-ID
The illustration shows the configuration on the Dell Networking system before connecting the end user
device in black and blue text, and after connecting the device in red text. The blue text corresponds to
the preceding numbered steps on dynamic VLAN assignment with 802.1X.
120
Enable
FORCE_AUTHORIZED
UNAUTHORIZED
Disable
None
Disable
NONE
Disable
NONE
NONE
90 seconds
120 seconds
10
15 seconds
15 seconds
7200 seconds
10
SINGLE_HOST
Initialize
Initialize
802.1X

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents