Alcatel OmniSwitch 6600 Family Network Configuration Manual page 468

Omniswitch 6600 series
Hide thumbs Also See for OmniSwitch 6600 Family:
Table of Contents

Advertisement

Configuring Access Guardian Policies
Supplicant Policy Command Example
802.1x 1/48 supplicant policy authentication
group-mobility vlan 127 default-vlan
Configuring Non-supplicant Policies
Non-supplicant policies are used to classify non-802.1x devices connected to 802.1x-enabled switch ports.
There are two types of non-supplicant policies. One type uses MAC authentication to verify the non-
802.1x device. The second type does not perform any authentication and limits device assignment only to
those VLANs that are not authenticated VLANs.
To configure a non-supplicant policy that will perform MAC authentication, use the
cant policy authentication
ify one or more policies for classifying devices:
supplicant policy keywords
group mobility
vlan
default-vlan
block
pass
fail
When multiple policies are specified, the policy is referred to as a compound non-supplicant policy. Note
that the order in which parameters are configured determines the order in which they are applied.
To configure a compound non-supplicant policy, use the pass and fail keywords to specify which policies
to apply when MAC authentication is successful but does not return a VLAN ID and which policies to
apply when MAC authentication fails. The pass keyword is implied and therefore an optional keyword. If
the fail keyword is not used, the default action is to block the device when authentication fails.
Note. When a policy is specified as a policy to apply when authentication fails, device classification is
restricted to assigning non-supplicant devices to VLANs that are not authenticated VLANs.
To configure a non-supplicant policy that will not perform MAC authentication, use the
supplicant policy
command. The following keywords are available with this command to specify one or
more policies for classifying devices
supplicant policy keywords
group mobility
vlan
default-vlan
block
page 22-16
command. The following keywords are available with this command to spec-
:
OmniSwitch 6600 Family Network Configuration Guide
Description
If the 802.1x authentication process is successful
but does not return a VLAN ID for the device, then
the following occurs:
1
Group Mobility rules are applied.
If Group Mobility classification fails, then the
2
device is assigned to VLAN 127.
If VLAN 127 does not exist, then the device is
3
assigned to the default VLAN for port 1/48.
If the device fails 802.1x authentication, the device
is blocked on port 1/48.
Configuring 802.1X
802.1x non-suppli-
802.1x non-
April 2006

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents