117
shows the way that the network access device handles guest VLANs for MAC
authentication users.
Table 11 VLAN manipulation
Authentication status
VLAN manipulation
A user in the MAC authentication
guest VLAN fails MAC
authentication for any other
reason than server unreachable.
The user is still in the MAC authentication guest VLAN.
A user in the MAC authentication
guest VLAN passes MAC
authentication.
The device remaps the MAC address of the user to the authorization
VLAN assigned by the authentication server.
If no authorization VLAN is configured for the user on the authentication
server, the device remaps the MAC address of the user to the PVID of
the port.
Critical VLAN
The MAC authentication critical VLAN on a port accommodates users that fail MAC authentication
because no RADIUS authentication servers are reachable. Users in a MAC authentication critical
VLAN can access only network resources in the critical VLAN.
The critical VLAN feature takes effect when MAC authentication is performed only through RADIUS
servers. If a MAC authentication user fails local authentication after RADIUS authentication, the user
is not assigned to the critical VLAN. For more information about the authentication methods, see
"
."
shows the way that the network access device handles critical VLANs for MAC
authentication users.
Table 12 VLAN manipulation
Authentication status
VLAN manipulation
A user fails MAC authentication because all the
RADIUS servers are unreachable.
The device maps the MAC address of the user to the MAC
authentication critical VLAN.
The user is still in the MAC authentication critical VLAN if
the user fails MAC reauthentication because all the
RADIUS servers are unreachable.
If no MAC authentication critical VLAN is configured, the
device maps the MAC address of the user to the PVID of
the port.
A user in the MAC authentication critical VLAN
fails MAC authentication for any other reason
than server unreachable.
If a guest VLAN has been configured, the device maps the
MAC address of the user to the guest VLAN.
If no guest VLAN is configured, the device maps the MAC
address of the user to the PVID of the port.
A user in the MAC authentication critical VLAN
passes MAC authentication.
The device remaps the MAC address of the user to the
authorization VLAN assigned by the authentication server.
If no authorization VLAN is configured for the user on the
authentication server, the device remaps the MAC
address of the user to the PVID of the access port.
Critical voice VLAN
The MAC authentication critical voice VLAN on a port accommodates MAC authentication voice
users that have failed authentication because none of the RADIUS servers in their ISP domain is
reachable.
The critical VLAN feature takes effect when MAC authentication is performed only through RADIUS
servers. If a MAC authentication user fails local authentication after RADIUS authentication, the user
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...