Configuring An 802.1X Critical Vlan - HP 5120 SI Series Security Configuration Manual

Hide thumbs Also See for 5120 SI Series:
Table of Contents

Advertisement

member. For more information about the MAC-based VLAN function, see the Layer 2
Switching Configuration Guide.
Follow these steps to configure an Auth-Fail VLAN:
To do...
Enter system view
Enter Layer 2 Ethernet interface
view
Configure the Auth-Fail VLAN on
the port

Configuring an 802.1X critical VLAN

Configuration guidelines
Assign different IDs for the voice VLAN, the port VLAN, and the 802.1X critical VLAN on a port, so
the port can correctly process VLAN tagged incoming traffic.
You can configure only one 802.1X critical VLAN on a port. The 802.1X critical VLANs on different
ports can be different.
Configuration prerequisites
Create the VLAN to be specified as a critical VLAN.
If the 802.1X-enabled port performs port-based access control, enable 802.1X multicast trigger
(dot1x multicast-trigger).
If the 802.1X-enabled port performs MAC-based access control, configure the port as a hybrid port,
enable MAC-based VLAN on the port, and assign the port to the Auth-Fail VLAN as an untagged
member. For more information about the MAC-based VLAN function, see Layer 2
Configuration Guide.
Configuration procedure
Follow these steps to configure an 802.1X critical VLAN:
To do...
Enter system view
Enter Layer 2 Ethernet interface
view
Configure an 802.1X critical
VLAN on the port
Configure the port to trigger
802.1X authentication on
detection of a reachable
authentication server for users in
the critical VLAN
Use the command...
system-view
interface interface-type
interface-number
dot1x auth-fail vlan authfail-vlan-id
Use the command...
system-view
interface interface-type
interface-number
dot1x critical vlan vlan-id
dot1x critical recovery-action
reinitialize
80
Remarks
Required
By default, no Auth-Fail VLAN is
configured.
LAN Switching
Remarks
Required
By default, no critical VLAN is
configured.
Optional
By default, when a reachable
RADIUS server is detected, the
system removes the port or 802.1X
users from the critical VLAN
without triggering authentication.
LAN

Advertisement

Table of Contents
loading

Table of Contents