13-73
Configuring Port-Based and User-Based Access Control (802.1X)
How RADIUS/802.1X Authentication Affects VLAN Operation
■
VLAN 33 becomes unavailable to port 2 for the duration of the session
(because there can be only one untagged VLAN on any port).
To view the temporary VLAN assignment as a change in the active configura-
tion, use the
show vlan <
vlan-id
>
command as shown in Figure 13-20 where
<
vlan-id
>
is the (static or dynamic) VLAN used in the authenticated client
session.
Figure 13-20. The Active Configuration for VLAN 22 Temporarily Changes for the 802.1X Session
However, as shown in Figure 13-20, because VLAN 33 is configured as
untagged on port 2 and because a port can be untagged on only one VLAN,
port 2 loses access to VLAN 33 for the duration of the 802.1X session on VLAN
22.
You can verify the temporary loss of access to VLAN 33 by entering the
show
vlan 33
command as shown in Figure 13-21.
HP Switch(config)# show vlan 22
Status and Counters - VLAN Information - VLAN 22
VLAN ID : 22
Name : vlan 22
Status : Static
Voice : No
Jumbo : No
Port Information Mode Unknown VLAN Status
---------------- -------- ------------ ----------
1 Tagged Learn Up
2 802.1X Learn Up
4 Tagged Learn Up
.
.
.
Overriden Port VLAN configuration
Port Mode
---- ----------
2 No
This entry shows that port 2 is temporarily untagged on
VLAN 22 for an 802.1X session. This is to accommodate
an 802.1X client’s access, authenticated by a RADIUS
server, where the server included an instruction to put
the client’s access on VLAN 22.
Note:
With the current VLAN configuration (figure 13-20),
the only time port 2 appears in this
show vlan 22
listing
is during an 802.1X session with an attached client.
Otherwise, port 2 is not listed.
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......