Configuring Port-Based and Client-Based Access Control (802.1X)
802.1X Open VLAN Mode
Condition
Rule
Effect of RADIUS-assigned VLAN
The port joins the RADIUS-assigned VLAN as an untagged member.
This rule assumes no other authenticated
clients are already using the port on a
different VLAN.
IP Addressing for a Client Connected A client can either acquire an IP address from a DHCP server or use
to a Port Configured for 802.x Open
a manually configured IP address before connecting to the switch.
VLAN Mode
802.1X Supplicant Software for a
A friendly client, without 802.1X supplicant software, connecting to an
Client Connected to a Port Configured authenticator port must be able to download this software from the
for 802.1X Open VLAN Mode
Unauthorized-Client VLAN before authentication can begin.
Switch with a Port Configured To
When a new client is authenticated on a given port:
Allow Multiple Authorized-Client
•
Sessions
•
If no other clients are authenticated on that port, then the port joins
one VLAN in the following order of precedence:
a. A RADIUS-assigned VLAN, if configured.
b. An Authenticated-Client VLAN, if configured.
c. A static, port-based VLAN to which the port belongs as an
untagged member.
d. Any VLAN(s) to which the port is configured as a tagged
member (provided that the client can operate in that VLAN).
If another client is already authenticated on the port, then the port
is already assigned to a VLAN for the previously-existing client
session, and the new client must operate in this same VLAN,
regardless of other factors. (This means that a client without 802.1X
client authentication software cannot access a configured,
Unauthenticated-Client VLAN if another, authenticated client is
already using the port.)
10-33
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......