Configuring An 802.1X Auth-Fail Vlan; Configuration Guidelines - HPE FlexNetwork 5510 HI Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 5510 HI Series:
Table of Contents

Advertisement

This feature does not take effect if the 802.1 X authentication is triggered by EAPOL-Start packets
from 802.1X clients.
To use this feature, the 802.1X-enabled port must be configured with the unicast trigger feature and
perform MAC-based access control.
When 802.1X authentication is triggered on a port, the device performs the following operations:
1.
Sends a unicast EAP-Request/Identity packet to the MAC address that triggers the
authentication.
2.
Retransmits the packet if no response is received within the username request timeout interval
set by using the dot1x timer tx-period command.
3.
Assigns the port to the 802.1X guest VLAN after the maximum number of request attempts set
by using the dot1x retry command is reached.
To enable 802.1X guest VLAN assignment delay on a port:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Enable
VLAN assignment delay
on the port.

Configuring an 802.1X Auth-Fail VLAN

Configuration guidelines

When you configure an 802.1X Auth-Fail VLAN, follow these restrictions and guidelines:
Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X Auth-Fail VLAN on a
port. The assignment ensures that the port can correctly process VLAN-tagged incoming traffic.
You can configure only one 802.1X Auth-Fail VLAN on a port. The 802.1X Auth-Fail VLANs on
different ports can be different.
When you configure multiple security features on a port, follow the guidelines in
Table 8 Relationships of the 802.1X Auth-Fail VLAN with other features
Feature
Super VLAN
MAC authentication guest VLAN
on
a
port
MAC-based access control
Port intrusion protection actions
on
a
port
MAC-based access control
Command
system-view
interface
interface-number
802.1X
guest
dot1x guest-vlan-delay
Relationship description
You cannot specify a VLAN as
both a super VLAN and an 802.1X
Auth-Fail VLAN.
The 802.1X Auth-Fail VLAN has a
that
performs
high priority.
The
feature has higher priority than the
block MAC action.
that
performs
The
feature has lower priority than the
shutdown port action of the port
intrusion protection feature.
interface-type
802.1X
Auth-Fail
VLAN
802.1X
Auth-Fail
VLAN
89
Remarks
N/A
N/A
By
default,
802.1X
assignment delay is disabled on a port.
Reference
See Layer 2—LAN Switching
Configuration Guide.
See
"Configuring
authentication."
See
"Configuring port
guest
VLAN
Table
8.
MAC
security."

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents