Table 19-1. IEEE 802.1X Monitor Mode Behavior (Continued)
Case
RADIUS
Timeout
EAPOL Timeout Default behavior
Supplicant
Timeout
How Does the Authentication Server Assign DiffServ Filters?
The PowerConnect 7000 Series switches allow the external 802.1X
Authenticator or RADIUS server to assign DiffServ policies to users that
authenticate to the switch. When a host (supplicant) attempts to connect to
the network through a port, the switch contacts the 802.1X authenticator or
RADIUS server, which then provides information to the switch about which
DiffServ policy to assign the host (supplicant). The application of the policy
is applied to the host after the authentication process has completed.
512
Configuring 802.1X and Port-Based Security
Sub-case
Unauth VLAN
enabled
Default behavior
Unauth VLAN
enabled
Guest VLAN
enabled
MAB Success Case Port State: Permit
MAB Fail Case
Regular Dot1x
Port State: Permit
VLAN: Unauth
Port State: Deny
Port State: Deny
Port State: Deny
Port State: Permit
VLAN: Guest
VLAN: Assigned
Filter: Assigned
Port State: Deny
Port State: Deny
Dot1x Monitor Mode
Port State: Permit
VLAN: Unauth
Port State: Permit
VLAN: Default
Port State: Permit
VLAN: Unauth
Port State: Permit
VLAN: Default
Port State: Permit
VLAN: Guest
Port State: Permit
VLAN: Assigned
Filter: Assigned
Port State: Permit
VLAN: Default
Port State: Deny