Configuring An 802.1X Auth-Fail Vlan; Configuration Guidelines - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

Unicast trigger is enabled.
With this feature enabled, when a port receives a packet from an unknown MAC address, the device
performs the following operations:
1.
Sends a unicast EAP-Request/Identity packet to the MAC address.
2.
Retransmits the packet if no response has been received within the username request timeout
interval set by using the dot1x timer tx-period command.
3.
Assigns the port the 802.1X guest VLAN after the maximum number of request attempts set by
using the dot1x retry command is reached.
This feature does not take effect if the 802.1X guest VLAN assignment is triggered by 802.1X
protocol packets.
To enable 802.1X guest VLAN assignment delay on a port:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Enable 802.1X guest
VLAN assignment delay
on the port.

Configuring an 802.1X Auth-Fail VLAN

Configuration guidelines

When you configure an 802.1X Auth-Fail VLAN, follow these restrictions and guidelines:
Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X Auth-Fail VLAN on a port.
The assignment ensures that the port can correctly process VLAN-tagged incoming traffic.
You can configure only one 802.1X Auth-Fail VLAN on a port. The 802.1X Auth-Fail VLANs on
different ports can be different.
When you configure multiple security features on a port, follow the guidelines in
Table 8 Relationships of the 802.1X Auth-Fail VLAN with other features
Feature
Super VLAN
MAC authentication guest VLAN
on a port that performs
MAC-based access control
Port intrusion protection actions
on a port that performs
MAC-based access control
Command
system-view
interface interface-type
interface-number
dot1x guest-vlan-delay
Relationship description
You cannot specify a VLAN as
both a super VLAN and an 802.1X
Auth-Fail VLAN.
The 802.1X Auth-Fail VLAN has a
high priority.
The 802.1X Auth-Fail VLAN
feature has higher priority than the
block MAC action.
The 802.1X Auth-Fail VLAN
feature has lower priority than the
shutdown port action of the port
intrusion protection feature.
88
Remarks
N/A
N/A
By default, 802.1X guest VLAN
assignment delay is disabled on a port.
Reference
See Layer 2—LAN Switching
Configuration Guide.
See "Configuring MAC
authentication."
See "Configuring port security."
Table
8.

Advertisement

Table of Contents
loading

Table of Contents