ProSafe 7000 Managed Switch Software Administration Manual, Release 8.0.3
Security Management
13-21
v1.0, June 2010
c.
Select
Enable
in the Accounting Mode field.
d.
Click
Apply
.
Create a Guest VLAN
The Guest VLAN feature allows a switch to provide a distinguished service to dot1x unaware clients (not
rogue users who fail authentication). This feature provides a mechanism to allow visitors and contractors to
have network access to reach external network with no ability to surf internal LAN.
For a port in port-based mode,when a client that does not support 802.1X is connected to an unauthorized
port that is 802.1X enabled. Then the client does not respond to the 802.1X requests from the switch ,and the
port would remain in the unauthorized state, and the client is not granted access to the network. If the guest
VLAN was configured for that port then the port is placed in the configured guest VLAN and the port is
moved to authorized state allowing access to the client after a certain amount of time (determined by the
guest vlan period). If the client attached is 802.1x aware , then this allows the client to respond to 802.1X
requests from the switch..
RADIUS server
Switch
Host
Guest 1
Guest 2
1/0/1
1/0/24
1/0/12
1/0/6
Figure
13-22
For a port in mac-based mode, if traffic from a unauthenticated client is noticed on a port then , if guest
VLAN has been configured on the port, the guest VLAN timer is started for that client. If the client is 802.1x
unaware and does not respond to any 802.1x requests , when the guest vlan timer expires, the client is