Operation Manual – 802.1x-HABP-MAC Authentication
H3C S5500-EI Series Ethernet Switches
Chapter 1 802.1x Configuration
1-12
Note:
After an 802.1x supplicant passes authentication, the authentication server sends
authorization information to the authenticator. If the authorization information contains
VLAN authorization information, the authenticator adds the port connecting the
supplicant to the assigned VLAN. This neither changes nor affects the configurations of
the port. The only result is that the assigned VLAN takes precedence over the manually
configured one, that is, the assigned VLAN takes effect. After the supplicant goes
offline, the configured one takes effect.
1.1.8 Features Working Together with 802.1x
I. VLAN assigning
After an 802.1x user passes the authentication, the server will send an authorization
message to the device. If the server is enabled with the VLAN assigning function, the
assigned VLAN information will be included in the message. The device, depending on
the link type of the port used to log in, adds the port to the assigned VLAN according to
the following rules:
z
If the port link type is Access, the port leaves its current VLAN and joins the
assigned VLAN.
z
If the port link type is Trunk, the assigned VLAN is allowed to pass the current
trunk port. The default VLAN ID of the port is that of the assigned VLAN.
z
If the port link type is Hybrid, the assigned VLAN is allowed to pass the current port
without carrying the tag. The default VLAN ID of the port is that of the assigned
VLAN.
The assigned VLAN neither changes nor affects the configuration of a port. However,
as the assigned VLAN has higher priority than the user-configured VLAN, it is the
assigned VLAN that takes effect after a user passes authentication. After the user goes
offline, the port returns to its original VLAN.
For details about VLAN configuration, refer to
VLAN Configuration
.
Note:
z
With a Hybrid port, the VLAN assigning will fail if you have configured the assigned
VLAN to carry tags.
z
With a Hybrid port, you cannot configure an assigned VLAN to carry tags after the
VLAN has been assigned.