Eapol Port States; Guest Vlan - IBM RackSwitch G8000 Application Manual

A top-of-rack (tor) switch
Hide thumbs Also See for RackSwitch G8000:
Table of Contents

Advertisement

EAPoL Port States

Guest VLAN

© Copyright IBM Corp. 2011
The state of the port determines whether the client is granted access to the network,
as follows:
Unauthorized
While in this state the port discards all ingress and egress traffic except EAP
packets.
Authorized
When the client is successfully authenticated, the port transitions to the
authorized state allowing all traffic to and from the client to flow normally.
Force Unauthorized
You can configure this state that denies all access to the port.
Force Authorized
You can configure this state that allows full access to the port.
Use the 802.1X global configuration commands (dot1x) to configure 802.1X
authentication for all ports in the switch. Use the 802.1X port commands to
configure a single port.
The guest VLAN provides limited access to unauthenticated ports. The guest VLAN
can be configured using the following commands:
RS G8000(config)#
dot1x guest-vlan ?
Client ports that have not received an EAPOL response are placed into the Guest
VLAN, if one is configured on the switch. Once the port is authenticated, it is moved
from the Guest VLAN to its configured VLAN.
When Guest VLAN enabled, the following considerations apply while a port is in the
unauthenticated state:
The port is placed in the guest VLAN.
The Port VLAN ID (PVID) is changed to the Guest VLAN ID.
Port tagging is disabled on the port.
Chapter 6. 802.1X Port-Based Network Access Control
75

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents