Configuring An 802.1X Guest Vlan; Configuration Guidelines; Configuration Prerequisites - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuring an 802.1X guest VLAN

Configuration guidelines

When you configure an 802.1X guest VLAN, follow these guidelines:
The following matrix shows the location restrictions for the interface configured with 802.1X
guest VLAN and the interface connected to the external network on an eIRF system:
Location of the interface configured
with 802.1X guest VLAN
A PEX
An interface module on the parent fabric
For more information about eIRF, see Virtual Technologies Configuration Guide.
You can configure only one 802.1X guest VLAN on a port. The 802.1X guest VLANs on different
ports can be different.
Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X guest VLAN on a port.
The assignment makes sure the port can correctly process incoming VLAN-tagged traffic.
When you configure multiple security features on a port, follow the guidelines in
Table 7 Relationships of the 802.1X guest VLAN and other security features
Feature
Super VLAN
MAC authentication
guest VLAN on a port
that performs
MAC-based access
control
802.1X Auth-Fail VLAN
on a port that performs
MAC-based access
control
Port intrusion protection
actions on a port that
performs MAC-based
access control

Configuration prerequisites

Before you configure an 802.1X guest VLAN, complete the following tasks:
Create the VLAN to be specified as the 802.1X guest VLAN.
Location restrictions of the interface
connected to the external network
The interface cannot be on an interface module of
the parent fabric or on other PEXs.
The interface cannot be on PEXs.
Relationship description
You cannot specify a VLAN as both a super
VLAN and an 802.1X guest VLAN.
Only the 802.1X guest VLAN takes effect. A
user that fails MAC authentication will not be
assigned to the MAC authentication guest
VLAN.
The 802.1X Auth-Fail VLAN has a higher
priority than the 802.1X guest VLAN.
The 802.1X guest VLAN feature has higher
priority than the block MAC action.
The 802.1X guest VLAN feature has lower
priority than the shutdown port action of the
port intrusion protection feature.
93
Table
7.
Reference
See Layer 2—LAN
Switching Configuration
Guide.
See
"Configuring MAC
authentication."
See
"802.1X VLAN
manipulation."
See
"Configuring port
security."

Advertisement

Table of Contents
loading

Table of Contents