Page 166
Port Access Control
Figure 122. Port Access Control Configuration Page
Table 91. Port Access Control Configuration Fields
Field
Description
Global Port Access Control Fields
Administrative Mode
Select Enable or Disable 802.1x mode on the switch. The default is Disable. This feature
permits port-based authentication on the switch.
VLAN Assignment Mode
If enabled, when a supplicant is authenticated by a authentication server, the port that the
supplicant is connected to is placed in a particular VLAN specified by the RADIUS server.
VLAN Assignment mode controls if the switch is allowed to place a port in a RADIUS-
assigned VLAN. A port’s VLAN assignment is determined by the first supplicant that is
authenticated on the port.
Dynamic VLAN Creation
Mode
The administrative mode of dynamic VLAN creation on the device. If RADIUS-assigned
VLANs are enabled, the RADIUS server is expected to include the VLAN ID in the 802.1X
tunnel attributes of its response message to the device. If dynamic VLAN creation is enabled
on the device and the RADIUS-assigned VLAN does not exist, then the assigned VLAN is
dynamically created. This implies that the client can connect from any port and can get
assigned to the appropriate VLAN. This feature gives flexibility for clients to move around the
network without much additional configuration required.