Configuring A Vlan Group; Configuring An 802.1X Guest Vlan; Configuration Guidelines - HP 3600 v2 Series Configuration Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

To set the maximum number of 802.1X authentication attempts for MAC authentication users:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet interface
view.
3.
Set the maximum number of
802.1X authentication attempts
for MAC authentication users.

Configuring a VLAN group

Step
1.
Enter system view.
2.
Create a VLAN group and
enter its view.
3.
Add VLANs to the group.

Configuring an 802.1X guest VLAN

Configuration guidelines

Follow these guidelines when you configure an 802.1X guest VLAN:
You can configure only one 802.1X guest VLAN on a port. The 802.1X guest VLANs on different
ports can be different.
Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X guest VLAN on a port, so
the port can correctly process incoming VLAN tagged traffic.
With 802.1X authentication, a hybrid port is always assigned to a VLAN as an untagged member.
After the assignment, do not reconfigure the port as a tagged member in the VLAN.
If 802.1X clients in your network cannot trigger an immediate DHCP-assigned IP address renewal in
response to a VLAN change, the 802.1X users cannot access authorized network resources
immediately after an 802.1X authentication is complete. As a solution, remind the 802.1X users to
release their IP addresses or repair their network connections for a DHCP reassignment after
802.1X authentication is complete. The HP iNode client does not have this problem.
Use
Table 8
Command
system-view
interface interface-type
interface-number
dot1x attempts max-fail
unsuccessful-attempts
Command
system-view
vlan-group group-name
vlan-list vlan-list
when configuring multiple security features on a port.
Remarks
N/A
By default, no VLAN group exists.
By default, a VLAN group does not
contain VLANs.
You can repeat this step to add VLANs.
Do not add a super VLAN to a VLAN
group. The device does not assign
super VLANs to 802.1X users.
89
Remarks
N/A
N/A
By default, an authenticated MAC
authentication user can retry
802.1X authentication until the
maximum number of authentication
attempts configured on the 802.1X
client is reached.

Advertisement

Table of Contents
loading

Table of Contents