Configuring An 802.1X Guest Vlan; Configuration Guidelines; Configuration Prerequisites - HP FlexFabric 5700 Series Security Configuration Manual

Hide thumbs Also See for FlexFabric 5700 Series:
Table of Contents

Advertisement

Step
2.
(Optional.) Set the periodic
reauthentication timer.
3.
Enter Layer 2 Ethernet
interface view.
4.
Enable periodic online user
reauthentication.
5.
(Optional.) Enable the
keep-online feature for 802.1X
users.

Configuring an 802.1X guest VLAN

Configuration guidelines

When you configure an 802.1X guest VLAN, follow these guidelines:
You can configure only one 802.1X guest VLAN on a port. The 802.1X guest VLANs on different
ports can be different.
Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X guest VLAN on a port. The
assignment makes sure the port can correctly process incoming VLAN-tagged traffic.
When you configure multiple security features on a port, follow the guidelines in
Table 7 Relationships of the 802.1X guest VLAN and other security features
Feature
802.1X Auth-Fail VLAN
on a port that performs
MAC-based access
control
Port intrusion protection
actions on a port that
performs MAC-based
access control

Configuration prerequisites

Before you configure an 802.1X guest VLAN, complete the following tasks:
Create the VLAN to be specified as the 802.1X guest VLAN.
If the 802.1X-enabled port performs MAC-based access control, perform the following operations
for the port:
Configure the port as a hybrid port.
Command
dot1x timer reauth-period
reauth-period-value
interface interface-type
interface-number
dot1x re-authenticate
dot1x re-authenticate
server-unreachable keep-online
Relationship description
The 802.1X Auth-Fail VLAN has a higher
priority than the 802.1X guest VLAN.
The 802.1X guest VLAN feature has higher
priority than the block MAC action.
The 802.1X guest VLAN feature has lower
priority than the shutdown port action of the port
intrusion protection feature.
86
Remarks
The default is 3600 seconds.
N/A
By default, the feature is disabled.
By default, this feature is disabled,
and the device logs off online
802.1X users if no authentication
server is reachable for 802.1X
reauthentication.
Table
Reference
See
"802.1X VLAN
manipulation."
See
"Configuring port
security."
7.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents