Configuration Prerequisites; Configuration Procedure; Configuring An Auth-Fail Vlan; Configuration Guidelines - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Feature
Port intrusion protection on
a port that performs
MAC-based access control

Configuration prerequisites

Create the VLAN to be specified as the 802.1X guest VLAN.
If the 802.1X-enabled port performs port-based access control, enable 802.1X multicast trigger.
If the 802.1X-enabled port performs MAC-based access control, configure the port as a hybrid port,
enable MAC-based VLAN on the port, and assign the port to the 802.1X guest VLAN as an
untagged member. For more information about the MAC-based VLAN function, see Layer 2
Switching Configuration Guide.

Configuration procedure

To configure an 802.1X guest VLAN:
Step
1.
Enter system view.
2.
Configure an 802.1X guest
VLAN for one or more ports.

Configuring an Auth-Fail VLAN

Configuration guidelines

Follow these guidelines when configuring an 802.1X Auth-Fail VLAN:
Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X Auth-Fail VLAN on a port,
so the port can correctly process VLAN tagged incoming traffic.
You can configure only one 802.1X Auth-Fail VLAN on a port. The 802.1X Auth-Fail VLANs on
different ports can be different.
If 802.1X clients in your network cannot trigger an immediate DHCP-assigned IP address renewal
in response to a VLAN change, the 802.1X users cannot access authorized network resources
immediately after an 802.1X authentication is complete. As a solution, remind the 802.1X users to
release their IP addresses or repair their network connections for a DHCP reassignment after
802.1X authentication is complete. The HP iNode client does not have this problem.
Use
Table 7
Relationship description
The 802.1X guest VLAN function has higher
priority than the block MAC action but lower
priority than the shut down port action of the port
intrusion protection feature.
Command
system-view
(Approach 1) In system view:
dot1x guest-vlan guest-vlan-id
[ interface interface-list ]
(Approach 2) In Ethernet interface
view:
when configuring multiple security features on a port.
a.
interface interface-type
interface-number
b.
dot1x guest-vlan guest-vlan-id
95
Reference
See
"Configuring port
security."
Remarks
N/A
Use either approach.
By default, no 802.1X guest
VLAN is configured on any
port.
LAN

Advertisement

Table of Contents
loading

Table of Contents