104
Authorization VLAN
You can specify the authorization VLAN for a MAC authentication user to control access to
authorized network resources. The authorization VLAN of a MAC authorization user can be specified
on the device or be assigned by a remote server.
•
The device can resolve authorization VLANs assigned by a remote server in the form of VLAN
ID or VLAN name. The VLANs can be tagged or not.
•
The device can resolve authorization VLANs in the form of VLAN ID that are specified on itself
in local user view or user group view. The VLANs are untagged.
For more information about local authorization VLAN configuration, see "Configuring AAA."
When a MAC authentication user passes authentication, the authentication server (either the local
access device or a RADIUS server) assigns the user's authorization VLAN to the user. The port
through which the user accesses the device is assigned to the authorization VLAN. As a best
practice, always specify the authorization VLAN as an untagged VLAN if the port is a hybrid port.
After the VLAN assignment, do not reconfigure the port as a tagged member in the VLAN.
describes the way the network access device handles authorization VLANs for MAC
authenticated users.
Table 9 VLAN manipulation
Port type
VLAN manipulation
•
Access
port
•
Trunk
port
•
Hybrid
port
with
MAC-based-VLAN disabled
•
If the port is assigned to the authorization VLAN as an untagged
member, the device assigns the port to the first authenticated
user's authorization VLAN. The authorization VLAN becomes
the PVID. You must assign the same untagged authorization
VLAN to all MAC authentication users on the port. If a different
untagged authorization VLAN is assigned to a subsequent user,
the user cannot pass MAC authentication.
•
If the port is assigned to the authorization VLAN as a tagged
member, the PVID of the port does not change. The device
maps the MAC address of each user to its own authorization
VLAN.
NOTE:
An access port can be assigned to an authorization VLAN only as an
untagged VLAN member.
Hybrid port with MAC-based VLAN
enabled
The device maps the MAC address of each user to its own
authorization VLAN regardless of whether the port is a tagged
member. The PVID of the port does not change.
Guest VLAN
You can configure a MAC authentication guest VLAN on a port to accommodate users that have
failed MAC authentication on the port. Users in the MAC authentication guest VLAN can access a
limited set of network resources, such as a software server, to download software and system
patches. If no MAC authentication guest VLAN is configured, the users that have failed MAC
authentication cannot access any network resources.
A hybrid port is always assigned to a MAC authentication guest VLAN as an untagged member. After
the assignment, do not reconfigure the port as a tagged member in the VLAN.
shows the way that the network access device handles guest VLANs for MAC
authentication users.
Table 10 VLAN manipulation
Authentication status
VLAN manipulation
A user in the MAC authentication
guest VLAN fails MAC
The user is still in the MAC authentication guest VLAN.