Configuration Procedure; Configuring An 802.1X Auth-Fail Vlan; Configuration Guidelines; Configuration Prerequisites - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

If the 802.1X-enabled port performs MAC-based access control, perform the following
operations for the port:
Configure the port as a hybrid port.
Enable MAC-based VLAN on the port. For more information about MAC-based VLANs, see
Layer 2—LAN Switching Configuration Guide.
Assign the port to the 802.1X guest VLAN as an untagged member.

Configuration procedure

To configure an 802.1X guest VLAN:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Configure the 802.1X guest
VLAN on the port.

Configuring an 802.1X Auth-Fail VLAN

Configuration guidelines

When you configure an 802.1X Auth-Fail VLAN, follow these restrictions and guidelines:
Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X Auth-Fail VLAN on a port.
The assignment makes sure the port can correctly process VLAN-tagged incoming traffic.
You can configure only one 802.1X Auth-Fail VLAN on a port. The 802.1X Auth-Fail VLANs on
different ports can be different.
When you configure multiple security features on a port, follow the guidelines in
Table 8 Relationships of the 802.1X Auth-Fail VLAN with other features
Feature
Super VLAN
MAC authentication guest
VLAN on a port that performs
MAC-based access control
Port intrusion protection actions
on a port that performs
MAC-based access control

Configuration prerequisites

Before you configure an 802.1X Auth-Fail VLAN, complete the following tasks:
Command
system-view
interface interface-type
interface-number
dot1x guest-vlan guest-vlan-id
Relationship description
You cannot specify a VLAN as
both a super VLAN and an
802.1X Auth-Fail VLAN.
The 802.1X Auth-Fail VLAN has
a high priority.
The 802.1X Auth-Fail VLAN
feature has higher priority than
the block MAC action.
The 802.1X Auth-Fail VLAN
feature has lower priority than
the shutdown port action of the
port intrusion protection feature.
94
Remarks
N/A
N/A
By default, no 802.1X guest VLAN
is configured on any port.
Table
Reference
See Layer 2—LAN Switching
Configuration Guide.
See
"Configuring MAC
authentication."
See
"Configuring port
8.
security."

Advertisement

Table of Contents
loading

Table of Contents