13-30
Configuring Port-Based and User-Based Access Control (802.1X)
Configuring Switch Ports as 802.1X Authenticators
have access to the insecure guest VLAN (unauthenticated VLAN) that has been
configured for 802.1X or Web/MAC authentication. 802.1X and Web/MAC
authentication normally do not allow authenticated clients (the phone) and
unauthenticated clients (the PC) on the same port.
Mixed port access mode allows 802.1X and Web/MAC authenticated and
unauthenticated clients on the same port when the guest VLAN is the same as
the port’s current untagged authenticated VLAN for authenticated clients, or
when none of the authenticated clients are authorized on the untagged authen-
ticated VLAN. Instead of having just one client per port, multiple clients can
use the guest VLAN.
Authenticated clients always have precedence over guests (unauthenticated
clients) if access to a client’s untagged VLAN requires removal of a guest VLAN
from the port. If an authenticated client becomes authorized on its untagged
VLAN as the result of initial authentication or because of an untagged packet
from the client, then all 802.1X or Web/MAC authenticated guests are removed
from the port and the port becomes an untagged member of the client’s
untagged VLAN.
Characteristics of Mixed Port Access Mode
■
The port keeps tagged VLAN assignments continuously.
■
The port sends broadcast traffic from the VLANs even when there are only
guests authorized on the port.
■
Guests cannot be authorized on any tagged VLANs.
■
Guests can use the same bandwidth, rate limits and QoS settings that may
be assigned for authenticated clients on the port (via RADIUS attributes).
■
When no authenticated clients are authorized on the untagged authenti-
cated VLAN, the port becomes an untagged member of the guest VLAN
for as long as no untagged packets are received from any authenticated
clients on the port.
■
New guest authorizations are not allowed on the port if at least one
authenticated client is authorized on its untagged VLAN and the guest
VLAN is not the same as the authenticated client’s untagged VLAN.
N o t e
If you disable mixed port access mode, this does not automatically remove
guests that have already been authorized on a port where an authenticated
client exists. New guests are not allowed after the change, but the existing
authorized guests will still be authorized on the port until they are removed
by a new authentication, an untagged authorization, a port state change, and
so on.
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......