74
Table 6 VLAN manipulation
Port access control
method
VLAN manipulation
Port-based
The device assigns the port to the first authenticated user's authorization
VLAN. All subsequent 802.1X users can access the VLAN without
authentication.
If the port is assigned to the authorization VLAN as an untagged member,
the authorization VLAN becomes the PVID. If the port is assigned to the
authorization VLAN as a tagged member, the PVID of the port does not
change.
MAC-based
•
For a hybrid port with MAC-based VLAN enabled, the device maps the
MAC address of each user to its own authorization VLAN. The PVID of
the port does not change.
•
For an access, trunk, or MAC-based VLAN-disabled hybrid port:
{
If the port is assigned to the authorization VLAN as an untagged
member, the device assigns the port to the first authenticated user's
authorization VLAN. The authorization VLAN becomes the PVID.
To ensure successful authentication of subsequent users, authorize
the same VLAN to all 802.1X users on the port. If a different VLAN is
authorized to a subsequent user, the user cannot pass the
authentication.
{
If the port is assigned to the authorization VLAN as a tagged
member, the PVID of the port does not change. The device maps
the MAC address of each user to its own authorization VLAN.
IMPORTANT:
An 802.1X-enabled access port can be assigned to an authorization VLAN only as an untagged
VLAN member.
A hybrid port is always assigned to a VLAN as an untagged member. After the assignment, do not
reconfigure the port as a tagged member in the VLAN.
On a port enabled with periodic online user reauthentication, the MAC-based VLAN feature does not
take effect on a user who has been online before this feature was enabled. The access device
creates a MAC-to-VLAN mapping for the user when the following requirements are met:
•
The user passes reauthentication.
•
The authorization VLAN for the user is changed.
For more information about VLAN configuration and MAC-based VLANs, see
Layer 2—LAN
Switching Configuration Guide
.
Guest VLAN
The 802.1X guest VLAN on a port accommodates users who have not performed 802.1X
authentication. Users in the guest VLAN can access a limited set of network resources, such as a
software server, to download antivirus software and system patches. Once a user in the guest VLAN
passes 802.1X authentication, it is removed from the guest VLAN and can access authorized
network resources.
The access device handles VLANs on an 802.1X-enabled port based on its 802.1X access control
method.
•
On a port that performs port-based access control:
Authentication status
VLAN manipulation
A user has not passed 802.1X
The device assigns the 802.1X guest VLAN to the port as the PVID. All