Configuring An 802.1X Guest Vlan; Configuration Guidelines - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

If 802.1X clients in your network cannot trigger an immediate DHCP-assigned IP address renewal
in response to a VLAN change, the 802.1X users cannot access authorized network resources
immediately after an 802.1X authentication is complete. As a solution, remind the 802.1X users to
release their IP addresses or repair their network connections for a DHCP reassignment after
802.1X authentication is complete. The HP iNode client does not have this problem.
To configure a VLAN group:
Step
1.
Enter system view.
2.
Create a VLAN group and
enter its view.
3.
Add VLANs to the group.

Configuring an 802.1X guest VLAN

Configuration guidelines

Follow these guidelines when you configure an 802.1X guest VLAN:
You can configure only one 802.1X guest VLAN on a port. The 802.1X guest VLANs on different
ports can be different.
Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X guest VLAN on a port, so
the port can correctly process incoming VLAN tagged traffic.
If 802.1X clients in your network cannot trigger an immediate DHCP-assigned IP address renewal
in response to a VLAN change, the 802.1X users cannot access authorized network resources
immediately after an 802.1X authentication is complete. As a solution, remind the 802.1X users to
release their IP addresses or repair their network connections for a DHCP reassignment after
802.1X authentication is complete. The HP iNode client does not have this problem.
Use
Table 6
Table 6 Relationships of the 802.1X guest VLAN and other security features
Feature
Super VLAN
MAC authentication guest
VLAN on a port that
performs MAC-based
access control
802.1X Auth-Fail VLAN on
a port that performs
MAC-based access control
Command
system-view
vlan-group group-name
vlan-list vlan-list
when configuring multiple security features on a port.
Relationship description
You cannot specify a VLAN as both a super VLAN
and an 802.1X guest VLAN.
Only the 802.1X guest VLAN take effect. A user
who fails MAC authentication will not be assigned
to the MAC authentication guest VLAN.
The 802.1X Auth-Fail VLAN has a higher priority.
Remarks
N/A
By default, no VLAN group exists.
By default, a VLAN group contains no
VLANs.
You can repeat this step to add VLANs.
94
Reference
See Layer 2—LAN
Switching Configuration
Guide.
See
"Configuring MAC
authentication."
See
"Using 802.1X
authentication with other
features."

Advertisement

Table of Contents
loading

Table of Contents