Configuring Port-Based and User-Based Access Control (802.1X)
How RADIUS/802.1X Authentication Affects VLAN Operation
N o t e
You can use 802.1X (port-based or client-based) authentication and either Web
or MAC authentication at the same time on a port, with a maximum of eight
clients allowed on the port. (The default is one client.) Web authentication
and MAC authentication are mutually exclusive on the same port. Also, you
must disable LACP on ports configured for any of these authentication meth
ods. For more information, see “Web and MAC Authentication” on page 3-1 in
this guide.
VLAN Assignment on a Port
Following client authentication, VLAN configurations on a port are managed
as follows when you use 802.1X, MAC, or Web authentication:
■
The port resumes membership in any tagged VLANs for which it is already
assigned in the switch configuration. Tagged VLAN membership allows a
port to be a member of multiple VLANs simultaneously.
■
The port is temporarily assigned as a member of an untagged (static or
dynamic) VLAN for use during the client session according to the follow
ing order of options.
a. The port joins the VLAN to which it has been assigned by a RADIUS
server during client authentication.
b. If RADIUS authentication does not include assigning the port to a
VLAN, then the switch assigns the port to the authorized-client VLAN
configured for the authentication method.
c. If the port does not have an authorized-client VLAN configured, but
is configured for membership in an untagged VLAN, the switch
assigns the port to this untagged VLAN.
Operating Notes
■
During client authentication, a port assigned to a VLAN by a RADIUS
server or an authorized-client VLAN configuration is an untagged member
of the VLAN for the duration of the authenticated session. This applies
even if the port is also configured in the switch as a tagged member of the
same VLAN. The following restrictions apply:
•
If the port is assigned as a member of an untagged
static
VLAN, the
VLAN must already be configured on the switch. If the static VLAN
configuration does not exist, the authentication fails.
12-68
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...