Configuring Mac-Based Vlans - Dell PowerConnect B-FCXs Configuration Manual

Powerconnect b-series fcx
Hide thumbs Also See for PowerConnect B-FCXs:
Table of Contents

Advertisement

mac-authentication auth-fail-vlan-id 666
interface ethernet 0/1/1
mac-authentication mac-vlan max-mac-entries 5
mac-authentication mac-vlan 0030.4888.b9fe vlan 1 priority 1
mac-authentication mac-vlan enable
interface ethernet 0/1/2
mac-authentication mac-vlan max-mac-entries 10
mac-authentication mac-vlan enable
mac-authentication auth-fail-action restrict-vlan 222
interface ethernet 0/1/3
mac-authentication mac-vlan enable
mac-authentication auth-fail-action restrict-vlan
!
end

Configuring MAC-based VLANs

Configure MAC-based VLAN mapping on the switch statically for static hosts, or dynamically for
non-static hosts, by directing the RADIUS server to authenticate the incoming packet.
To configure the a MAC-based VLAN, first perform the following tasks:
NOTE
Do not configure MAC-based VLAN on ports that are tagged to any VLAN. Do not use ports on which
MAC-based VLAN is configured as tagged ports.
NOTE
For PowerConnect B-Series FCX devices, MAC-based VLAN with 802.1X will not work on the same
port if 802.1X has the RADIUS VLAN attribute defined as an untagged VLAN (for example U:1, U:2).
NOTE
MAC-based VLAN is not supported on trunk or LACP ports. Do not configure trunks on MAC-based
VLAN-enabled ports.
Using MAC-based VLANs and 802.1X security on the same port
On Dell PowerConnect devices, MAC-based VLANs and 802.1X security can be configured on the
same port. When both of these features are enabled on the same port, MAC-based VLAN is
performed prior to 802.1X authentication. If MAC-based VLAN is successful, 802.1X authentication
may be performed, based on the configuration of a vendor-specific attribute (VSA) in the profile for
the MAC address on the RADIUS server.
PowerConnect B-Series FCX Configuration Guide
53-1002266-01
In the VLANs, configure mac-vlan-permit for each port that will be participating in the
MAC-based VLAN
If a port has been MAC-based VLAN-enabled, but has not been added as mac-vlan-permit in
any of the VLANs, any MAC addresses learned on this port will be blocked in the reserved
VLAN. To prevent this, you must create all of the VLANs and add all ports as mac-vlan-permit
before enabling MAC-based VLAN on any ports.
Disable any multi-device port authentication on ports you will be using for MAC-to-VLAN
mapping
Configuring MAC-based VLANs
15
531

Advertisement

Table of Contents
loading

Table of Contents