Configuring An 802.1X Auth-Fail Vlan; Configuration Guidelines; Configuration Prerequisites; Configuration Procedure - HP 3600 v2 Series Configuration Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

Configuring an 802.1X Auth-Fail VLAN

Configuration guidelines

Follow these guidelines when configuring an 802.1X Auth-Fail VLAN:
Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X Auth-Fail VLAN on a port,
so the port can correctly process VLAN tagged incoming traffic.
You can configure only one 802.1X Auth-Fail VLAN on a port. The 802.1X Auth-Fail VLANs on
different ports can be different.
If 802.1X clients in your network cannot trigger an immediate DHCP-assigned IP address renewal in
response to a VLAN change, the 802.1X users cannot access authorized network resources
immediately after an 802.1X authentication is complete. As a solution, remind the 802.1X users to
release their IP addresses or repair their network connections for a DHCP reassignment after
802.1X authentication is complete. The HP iNode client does not have this problem.
Use
Table 9
Table 9 Relationships of the 802.1X Auth-Fail VLAN with other features
Feature
Super VLAN
MAC authentication guest VLAN
on a port that performs
MAC-based access control
Port intrusion protection on a port
that performs MAC-based access
control

Configuration prerequisites

Create the VLAN to be specified as the 802.1X Auth-Fail VLAN.
If the 802.1X-enabled port performs port-based access control, enable 802.1X multicast trigger
(dot1x multicast-trigger).
If the 802.1X-enabled port performs MAC-based access control, configure the port as a hybrid port,
enable MAC-based VLAN on the port, and assign the port to the Auth-Fail VLAN as an untagged
member. For more information about the MAC-based VLAN function, see Layer 2
Configuration Guide.

Configuration procedure

To configure an Auth-Fail VLAN:
when configuring multiple security features on a port.
Relationship description
You cannot specify a VLAN as both a super
VLAN and an 802.1X Auth-Fail VLAN.
The 802.1X Auth-Fail VLAN has a high
priority.
The 802.1X Auth-Fail VLAN function has
higher priority than the block MAC action
but lower priority than the shut down port
action of the port intrusion protection
feature.
91
Reference
See Layer 2
LAN
Switching Configuration
Guide
See
"Configuring MAC
authentication"
See
"Configuring port
security"
LAN Switching

Advertisement

Table of Contents
loading

Table of Contents