Specifying Supported Domain Name Delimiters - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

Feature
MAC authentication guest VLAN
on a port that performs
MAC-based access control
Before you configure an Auth-Fail VLAN, complete the following tasks:
Create the VLAN to be specified as the 802.1X Auth-Fail VLAN.
If the 802.1X-enabled port performs port-based access control, enable 802.1X multicast trigger.
If the 802.1X-enabled port performs MAC-based access control, configure the port as a hybrid port,
enable MAC-based VLAN on the port, and assign the port to the Auth-Fail VLAN as an untagged
member. For more information about the MAC-based VLAN function, see Layer 2—LAN Switching
Configuration Guide.
To configure an Auth-Fail VLAN:
Step
1.
Enter system view.
Enter Ethernet interface view.
2.
3.
Configure the Auth-Fail VLAN
on the port.

Specifying supported domain name delimiters

By default, the access device supports the at sign (@) as the delimiter. You can also configure the access
device to accommodate 802.1X users that use other domain name delimiters.
The configurable delimiters include the at sign (@), back slash (\), and forward slash (/).
If an 802.1X username string contains multiple configured delimiters, the leftmost delimiter is the domain
name delimiter. For example, if you configure @, /, and \ as delimiters, the domain name delimiter for
the username string 123/22\@abc is the forward slash (/).
If a username string contains none of the delimiters, the access device authenticates the user in the
mandatory or default ISP domain. The access selects a domain delimiter from the delimiter set in this
order: @, /, and \.
To specify a set of domain name delimiters:
Step
1.
Enter system view.
2.
Specify a set of domain name
delimiters for 802.1X users.
Relationship description
The 802.1X Auth-Fail VLAN has a high
priority.
Command
system-view
interface interface-type
interface-number
dot1x auth-fail vlan authfail-vlan-id
Command
system-view
dot1x domain-delimiter string
88
Reference
See
"Configuring MAC
authentication"
Remarks
N/A
N/A
By default, no Auth-Fail VLAN is
configured.
Remarks
N/A
By default, only the at sign (@)
delimiter is supported.

Advertisement

Table of Contents
loading

Table of Contents