802.1x Commands
859
Guest VLAN
The Guest VLAN feature allows a PowerConnect switch to provide a
distinguished service to unauthenticated users (not rogue users who fail
authentication). This feature provides a mechanism to allow visitors and
contractors to have network access to reach external network with no ability
to surf internal LAN.
When a client that does not support 802.1X is connected to an unauthorized
port that is 802.1X-enabled, the client does not respond to the 802.1X
requests from the switch. Therefore, the port remains in the unauthorized
state, and the client is not granted access to the network. If a guest VLAN is
configured for that port, then the port is placed in the configured guest
VLAN, and the port is moved to the authorized state, allowing access to the
client.
802.1x Monitor Mode
Monitor mode is a special mode that can be enabled in conjunction with
Dot1x authentication. It allows network access even in case where there is a
failure to authenticate but logs the results of the authentication process for
diagnostic purposes. The exact details are described in the below sections.
The main aim of the monitor mode is to provide a mechanism to the operator
to be able to identify the short-comings in the configuration of a Dot1x
authentication on the switch without affecting the network access to the
users of the switch.
There are three important aspects to this feature after activation:
1
To allow successful authentications using the returned information from
authentication server.
2
To provide a mechanism to report unsuccessful authentications without
negative repercussions to the user due to operator errors or failure cases
from the Authentication server or supplicants.
3
To accurately report the data received from the successful and
unsuccessful operations so that the operator can make the appropriate
changes or learn where the problem areas are.
The monitor mode can be configured globally on a switch. If the switch fails
to authenticate the user for any reason (say RADIUS access reject from
RADIUS server, RADIUS time-out, or the client itself is Dot1x unaware), the
2CSPC4.X7000-SWUM204.book Page 859 Friday, March 15, 2013 8:22 AM
Содержание Networking 7048
Страница 76: ...Contents 76 ...
Страница 168: ...Command Groups 168 ...
Страница 242: ...Using the CLI 242 ...
Страница 244: ...244 Layer 2 Switching Commands ...
Страница 278: ...278 AAA Commands ...
Страница 287: ...Administrative Profiles Commands 287 global config ethernet config port channel config ...
Страница 288: ...288 Administrative Profiles Commands ...
Страница 326: ...326 Address Table Commands Maximum addresses 100 Learned addresses ...
Страница 332: ...332 Auto VoIP Commands ...
Страница 366: ...366 DHCP Management Interface Commands ...
Страница 464: ...464 Ethernet CFM Commands ...
Страница 478: ...478 Green Ethernet Commands ...
Страница 502: ...502 IGMP Snooping Commands ...
Страница 542: ...542 IPv6 Access List Commands ...
Страница 554: ...554 IPv6 MLD Snooping Commands ...
Страница 568: ...568 IP Source Guard Commands ...
Страница 580: ...580 iSCSI Optimization Commands ...
Страница 588: ...588 Link Dependency Commands ...
Страница 616: ...616 LLDP Commands ...
Страница 652: ...652 Port Channel Commands ...
Страница 656: ...656 Port Monitor Commands Session ID Admin Mode Probe Port Mirrored Port Type 1 Enable 1 0 10 1 0 8 Rx Tx ...
Страница 752: ...752 RADIUS Commands ...
Страница 784: ...784 Spanning Tree Commands ...
Страница 850: ...850 VLAN Commands ...
Страница 856: ...856 Voice VLAN Commands ...
Страница 888: ...888 802 1x Commands console show dot1x advanced gigabitethernet 1 0 2 Port Guest Unauthenticated VLAN Vlan 1 0 2 10 20 ...
Страница 890: ...890 Layer 3 Commands ...
Страница 934: ...934 DHCP Server and Relay Agent Commands ...
Страница 952: ...952 DHCPv6 Commands DHCPv6 Relay forward Packets Transmitted 0 Total DHCPv6 Packets Transmitted 0 ...
Страница 960: ...960 DVMRP Commands ...
Страница 980: ...980 IGMP Commands ...
Страница 988: ...988 IGMP Proxy Commands ...
Страница 1036: ...1036 IP Routing Commands ...
Страница 1109: ...IPv6 Routing Commands 1109 Tracing route over a maximum of 20 hops 1 N N N ...
Страница 1110: ...1110 IPv6 Routing Commands ...
Страница 1114: ...1114 Loopback Interface Commands ...
Страница 1144: ...1144 Multicast Commands ...
Страница 1296: ...1296 OSPFv3 Commands ...
Страница 1306: ...1306 Router Discovery Protocol Commands ...
Страница 1322: ...1322 Routing Information Protocol Commands console config router split horizon none ...
Страница 1328: ...1328 Tunnel Interface Commands ...
Страница 1354: ...1354 Utility Commands ...
Страница 1364: ...1364 Auto Install Commands ...
Страница 1406: ...1406 CLI Macro Commands ...
Страница 1424: ...1424 Clock Commands ...
Страница 1430: ...1430 Command Line Configuration Scripting Commands ...
Страница 1451: ...Configuration and Image File Commands 1451 console ...
Страница 1452: ...1452 Configuration and Image File Commands ...
Страница 1482: ...1482 Mode Commands ...
Страница 1517: ...Power Over Ethernet Commands 1517 Command Mode Privileged EXEC User Guidelines This command has no user guidelines ...
Страница 1518: ...1518 Power Over Ethernet Commands ...
Страница 1576: ...1576 Sflow Commands ...
Страница 1604: ...1604 SNMP Commands ...
Страница 1618: ...1618 SSH Commands ...
Страница 1640: ...1640 Syslog Commands ...
Страница 1708: ...1708 System Management Commands 5 ...
Страница 1716: ...1716 Terminal Length Commands ...
Страница 1734: ...1734 User Interface Commands Example The following example closes an active terminal session console quit ...
Страница 1786: ...1786 Appendix A List of Commands ...
Страница 1787: ...www dell com support dell com Printed in the U S A ...
Страница 1788: ......