![Cisco 350XG series Скачать руководство пользователя страница 465](http://html.mh-extra.com/html/cisco/350xg-series/350xg-series_administration-manual_67491465.webp)
Security: 802.1X Authentication
Overview
Cisco 350XG & 550XG Series 10G Stackable Managed Switches
449
20
•
A RADIUS server must support DVA with RADIUS attributes tunnel-type
(64) = VLAN (13), tunnel-media-type (65) = 802 (6), and tunnel-private-
group-id = a VLAN ID.
When the RADIUS-Assigned VLAN feature is enabled, the host modes behave as
follows:
•
Single-Host and Multi-Host Mode
Untagged traffic and tagged traffic belonging to the RADIUS-assigned
VLAN are bridged via this VLAN. All other traffic not belonging to
unauthenticated VLANs is discarded.
•
Multi-Sessions Mode
Untagged traffic and tagged traffic not belonging to the unauthenticated
VLANs arriving from the client are assigned to the RADIUS-assigned VLAN
using TCAM rules and are bridged via the VLAN.
The
following
table
describes
guest
VLAN
and
RADIUS
VLAN
Assignment
support
depending
on
authentication
method
and
port
mode.
Legend:
†
—The port mode supports the guest VLAN and RADIUS-VLAN assignment
N/S—The port mode does not support the authentication method.
Violation Mode
In single-host mode you can configure the action to be taken when an
unauthorized host on authorized port attempts to access the interface. This is
done in the
Host and Session Authentication
page.
RADIUS VLAN Assignment Support
Authentication
Method
Single-host
Multi-host
Multi-sessions
802.1x
†
†
†
MAC
†
†
†
WEB
N/S
N/S
N/S