Configuration Restrictions And Guidelines; Configuration Procedure - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Create the VLAN to be specified as the MAC authentication guest VLAN.
Configure the VLAN as an untagged member on the port.

Configuration restrictions and guidelines

When you configure the MAC authentication guest VLAN on a port, follow these restrictions and
guidelines:
The following table shows the relationships of the MAC authentication guest VLAN with other
security features:
Feature
Quiet feature of MAC
authentication
Super VLAN
Port intrusion protection
802.1X guest VLAN on a
port that performs
MAC-based access
control
Including user IP
addresses in the
authentication requests
The following matrix shows the location restrictions for the interface configured with MAC
authentication guest VLAN and the interface connected to the external network on an eIRF
system:
Location of the interface configured
with MAC authentication guest VLAN
A PEX
An interface module on the parent fabric
For more information about eIRF, see Virtual Technologies Configuration Guide.

Configuration procedure

To configure the MAC authentication guest VLAN on a port:
Relationship description
The MAC authentication guest VLAN
feature has higher priority.
When a user fails MAC authentication, the
user can access the resources in the guest
VLAN. The user's MAC address is not
marked as a silent MAC address.
You cannot specify a VLAN as both a
super VLAN and a MAC authentication
guest VLAN.
The guest VLAN feature has higher priority
than the block MAC action but lower
priority than the shutdown port action of the
port intrusion protection feature.
The MAC authentication guest VLAN does
not take effect. A user who fails MAC
authentication is not assigned to the MAC
authentication guest VLAN.
If the feature is configured, users in the
MAC authentication guest VLAN cannot
perform a new round of authentication.
Location restrictions of the interface
connected to the external network
The interface cannot be on an interface module of
the parent fabric or on other PEXs.
The interface cannot be on PEXs.
122
Reference
See
"Setting MAC
authentication
timers."
See Layer 2—LAN
Switching Configuration
Guide.
See
"Configuring port
security."
See
"Configuring
802.1X."
See
"Including user IP
addresses in MAC
authentication
requests."

Advertisement

Table of Contents
loading

Table of Contents