H3C SR8800-F Configuration Manual page 229

Comware 7 user access
Hide thumbs Also See for SR8800-F:
Table of Contents

Advertisement

Table 9 VLAN manipulation
Port type
Access port
Trunk port
Hybrid port
IMPORTANT:
As a best practice, always assign a hybrid port to a VLAN as an untagged member. After the
assignment, do not reconfigure the port as a tagged member in the VLAN.
Guest VLAN
The MAC authentication guest VLAN on a port accommodates users that have failed MAC
authentication for any reason other than server unreachable. For example, the VLAN
accommodates users with invalid passwords entered.
You can deploy a limited set of network resources in the MAC authentication guest VLAN. For
example, a software server for downloading software and system patches.
A hybrid port is always assigned to a MAC authentication guest VLAN as an untagged member. After
the assignment, do not reconfigure the port as a tagged member in the VLAN.
The device reauthenticates users in the MAC authentication guest VLAN at a specific interval.
10
shows the way that the network access device handles guest VLANs for MAC authentication
users.
Table 10 VLAN manipulation
Authentication status
A user in the MAC authentication
guest VLAN fails MAC
authentication for any reason
other than server unreachable.
A user in the MAC authentication
guest VLAN passes MAC
authentication.
Critical VLAN
The MAC authentication critical VLAN on a port accommodates users that have failed MAC
authentication because no RADIUS authentication servers are reachable. Users in a MAC
authentication critical VLAN can access only network resources in the critical VLAN.
The critical VLAN feature takes effect when MAC authentication is performed only through RADIUS
servers. If a MAC authentication user fails local authentication after RADIUS authentication, the user
VLAN manipulation
If the port is assigned to the authorization VLAN as an untagged
member, the device assigns the port to the first authenticated
user's authorization VLAN. The authorization VLAN becomes
the PVID. All MAC authentication users on the port must be
assigned the same authorization VLAN. If a different
authorization VLAN is assigned to a subsequent user, the user
cannot pass MAC authentication.
If the port is assigned to the authorization VLAN as a tagged
member, the PVID of the port does not change. The device
maps the MAC address of each user to its own authorization
VLAN.
NOTE:
An access port can be assigned to an authorization VLAN only as an
untagged VLAN member.
VLAN manipulation
The user is still in the MAC authentication guest VLAN.
The device remaps the MAC address of the user to the authorization
VLAN assigned by the authentication server.
If no authorization VLAN is configured for the user on the authentication
server, the device remaps the MAC address of the user to the PVID of
the port.
213
Table

Advertisement

Table of Contents
loading

Table of Contents