Configuring An 802.1X Auth-Fail Vlan - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

Feature
MAC authentication guest VLAN
on a port that performs
MAC-based access control
802.1X Auth-Fail VLAN on a port
that performs MAC-based access
control
Before you configure an 802.1X guest VLAN, complete the following tasks:
Create the VLAN to be specified as the 802.1X guest VLAN.
If the 802.1X-enabled port performs port-based access control, enable 802.1X multicast trigger.
If the 802.1X-enabled port performs MAC-based access control, configure the port as a hybrid port,
enable MAC-based VLAN on the port, and assign the port to the 802.1X guest VLAN as an
untagged member. For more information about the MAC-based VLAN function, see Layer 2—LAN
Switching Configuration Guide.
To configure an 802.1X guest VLAN:
Step
1.
Enter system view.
2.
Configure an 802.1X guest
VLAN for one or more ports in
system or Ethernet interface
view.

Configuring an 802.1X Auth-Fail VLAN

Follow these guidelines when you configure an 802.1X Auth-Fail VLAN
Assign different IDs to the PVID and the 1X Auth-Fail VLAN on a port, so the port can correctly
process VLAN tagged incoming traffic.
You can configure only one 802.1X Auth-Fail VLAN on a port. The 802.1X Auth-Fail VLANs on
different ports can be different.
Use
Table 7
Table 7 Relationships of the 802.1X Auth-Fail VLAN with other features
Feature
Super VLAN
Relationship description
Only the 802.1X guest VLAN take effect. A
user that fails MAC authentication will not
be assigned to the MAC authentication
guest VLAN.
The 802.1X Auth-Fail VLAN has a higher
priority.
Command
system-view
In system view:
dot1x guest-vlan guest-vlan-id
[ interface interface-list ]
In Ethernet interface view:
when configuring multiple security features on a port.
Relationship description
You cannot specify a VLAN as both a super
VLAN and an 802.1X Auth-Fail VLAN.
a.
interface interface-type
interface-number
b.
dot1x guest-vlan
guest-vlan-id
87
Reference
See
"Configuring MAC
authentication."
See
"Using 802.1X
authentication with other
features."
Remarks
N/A
By default, no 802.1X guest VLAN
is configured on any port.
Reference
See Layer 2—LAN
Switching Configuration
Guide

Advertisement

Table of Contents
loading

Table of Contents