Optional) Configuring A Restrict Vlan For 802.1X Authentication - Huawei AR1200-S Configuration Manual

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
5.3.14 (Optional) Configuring a Restrict VLAN for 802.1x
Authentication
If a user that fails to be authenticated wants to access some network resources, for example,
download the 802.1x client program and update the virus library, add the user to a restrict VLAN
so that the user can access resources in the restrict VLAN.
Context
If a user fails to be authenticated after the restrict VLAN function is enabled, the AR1200-S
adds the access interface of the user to the restrict VLAN. Users in the restrict VLAN can access
resources in the restrict VLAN without authentication but must be authenticated when they
access external resources.
A restrict VLAN can be configured in the system view and in the interface view.
Procedure
l
l
Issue 02 (2012-03-30)
NOTE
The configured restrict VLAN cannot be the default VLAN of the interface.
A super VLAN cannot be configured as a restrict VLAN.
If an interface is configured with the restrict VLAN, the interface cannot be added to the restrict VLAN
and the VLAN configured as the restrict VLAN cannot be deleted. Users in the VLAN that is the same as
the restrict VLAN can communicate with users in the restrict VLAN.
Configuring a restrict VLAN in the system view
1.
Run:
system-view
The system view is displayed.
2.
(Optional) Run:
dot1x restrict-vlan fail-times fail-times
The maximum number of authentication failures is set.
By default, the maximum number of authentication failures is 3.
3.
Run:
dot1x restrict-vlan vlan-id interface { interface-type interface-number1
[ to interface-number2 ] } &<1-10>
A restrict VLAN is configured on an interface.
By default, no restrict VLAN is configured on an interface.
Configuring a restrict VLAN in the interface view
1.
Run:
system-view
The system view is displayed.
2.
(Optional) Run:
dot1x restrict-vlan fail-times fail-times
The maximum number of authentication failures is set.
By default, the maximum number of authentication failures is 3.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
5 NAC Configuration
110

Advertisement

Table of Contents
loading

Table of Contents