![HP HP ProCurve Series 6600 Access Security Manual Download Page 688](http://html.mh-extra.com/html/hp/hp-procurve-series-6600/hp-procurve-series-6600_access-security-manual_163101688.webp)
13-76
Configuring Port-Based and User-Based Access Control (802.1X)
How RADIUS/802.1X Authentication Affects VLAN Operation
Enabling the Use of GVRP-Learned Dynamic VLANs
in Authentication Sessions
Syntax:
aaa port-access gvrp-vlans
Enables the use of dynamic VLANs (learned through GVRP)
in the temporary untagged VLAN assigned by a RADIUS
server on an authenticated port in an 802.1X, MAC, or Web
authentication session.
Enter the
no
form of this command to disable the use of GVRP-
learned VLANs in an authentication session.
For information on how to enable a switch to dynamically
create 802.1Q-compliant VLANs, see the chapter on “GVRP”
in the Advanced Traffic Management Guide.
Notes
:
1. If a port is assigned as a member of an untagged dynamic
VLAN, the dynamic VLAN configuration must exist at the
time of authentication and GVRP for port-access
authentication must be enabled on the switch.
If the dynamic VLAN does not exist or if you have not enabled
the use of a dynamic VLAN for authentication sessions on
the switch, the authentication fails.
2. After you enable dynamic VLAN assignment in an authen-
tication session, it is recommended that you use the
interface
unknown-vlans
command on a per-port basis to prevent
denial-of-service attacks. The
interface unknown-vlans
c
om-
mand allows you to:
• Disable the port from sending advertisements of existing
GVRP-created VLANs on the switch.
• Drop all GVRP advertisements received on the port.
For more information, refer to the chapter on “GVRP” in the
Advanced Traffic Management Guide.
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......