HP 6125G HP 6125G & 6125G/XG Blade Switches Layer 2 - LAN Switching Co - Page 121

Dynamic MAC-based VLAN, Configuration restrictions and guidelines, Configuration procedure

Page 121 highlights

• When a port is assigned to the corresponding VLAN in a MAC address-to-VLAN entry, but has not been assigned to the VLAN by using the port hybrid vlan command, the port sends packets from the VLAN with VLAN tags removed. • If you configure both static and dynamic MAC-based VLAN assignment on the same port, dynamic MAC-based VLAN assignment applies. • A port forwards frames matching MAC-to-VLAN entries according to the 802.1p priorities of the MAC-based VLANs. Dynamic MAC-based VLAN You can use dynamic MAC-based VLAN with access authentication (such as 802.1X authentication based on MAC addresses) to implement secure, flexible terminal access. After configuring dynamic MAC-based VLAN on the device, you must configure the username-to-VLAN entries on the access authentication server. When a user passes authentication of the access authentication server, the device obtains VLAN information from the server, generates a MAC address-to-VLAN entry by using the source MAC address of the user packet and the VLAN information, and assigns the port to the MAC-based VLAN. When the user goes offline, the device automatically deletes the MAC address-to-VLAN entry, and removes the port from the MAC-based VLAN. For more information about 802.1X and MAC authentication, see Security Configuration Guide. Configuration restrictions and guidelines When you configure a MAC-based VLAN, follow these guidelines: • MAC-based VLANs are available only on hybrid ports. • With dynamic MAC-based VLAN assignment enabled, packets are delivered to the CPU for processing. The packet processing mode has the highest priority and overrides the configuration of MAC learning limit and disabling of MAC address learning. When dynamic MAC-based VLAN assignment is enabled, do not configure the MAC learning limit or disable MAC address learning. • Do not use dynamic MAC-based VLAN assignment together with 802.X and MAC authentication. • In dynamic MAC-based VLAN assignment, the port that receives a packet with an unknown source MAC address can be successfully assigned to the matched VLAN only when the matched VLAN is a static VLAN. • The MAC-based VLAN feature is mainly configured on the downlink ports of the user access devices. Do not enable this function together with link aggregation. • With MSTP enabled, if a port is blocked in the MST instance (MSTI) of the target MAC-based VLAN, the port drops the received packets, instead of delivering them to the CPU. As a result, the receiving port will not be dynamically assigned to the corresponding VLAN. Do not configure dynamic MAC-based VLAN assignment together with MSTP, because the former is mainly configured on the access side. • When PVST is enabled, if the VLAN to which a port is to be assigned is not allowed by the port, the port is blocked. In this case, the port drops received packets instead of delivering them to the CPU, failing to complete dynamic MAC-based VLAN assignment. Do not configure dynamic MAC-based VLAN assignment together with PVST, because the former is mainly configured on the access side. Configuration procedure To configure static MAC-based VLAN assignment: 112

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231

112
When a port is assigned to the corresponding VLAN in a MAC address-to-VLAN entry, but has not
been assigned to the VLAN by using the
port hybrid vlan
command, the port sends packets from
the VLAN with VLAN tags removed.
If you configure both static and dynamic MAC-based VLAN assignment on the same port, dynamic
MAC-based VLAN assignment applies.
A port forwards frames matching MAC-to-VLAN entries according to the 802.1p priorities of the
MAC-based VLANs.
Dynamic MAC-based VLAN
You can use dynamic MAC-based VLAN with access authentication (such as 802.1X authentication
based on MAC addresses) to implement secure, flexible terminal access. After configuring dynamic
MAC-based VLAN on the device, you must configure the username-to-VLAN entries on the access
authentication server.
When a user passes authentication of the access authentication server, the device obtains VLAN
information from the server, generates a MAC address-to-VLAN entry by using the source MAC address
of the user packet and the VLAN information, and assigns the port to the MAC-based VLAN. When the
user goes offline, the device automatically deletes the MAC address-to-VLAN entry, and removes the port
from the MAC-based VLAN. For more information about 802.1X and MAC authentication, see
Security
Configuration Guide
.
Configuration restrictions and guidelines
When you configure a MAC-based VLAN, follow these guidelines:
MAC-based VLANs are available only on hybrid ports.
With dynamic MAC-based VLAN assignment enabled, packets are delivered to the CPU for
processing. The packet processing mode has the highest priority and overrides the configuration of
MAC learning limit and disabling of MAC address learning. When dynamic MAC-based VLAN
assignment is enabled, do not configure the MAC learning limit or disable MAC address learning.
Do not use dynamic MAC-based VLAN assignment together with 802.X and MAC authentication.
In dynamic MAC-based VLAN assignment, the port that receives a packet with an unknown source
MAC address can be successfully assigned to the matched VLAN only when the matched VLAN is
a static VLAN.
The MAC-based VLAN feature is mainly configured on the downlink ports of the user access
devices. Do not enable this function together with link aggregation.
With MSTP enabled, if a port is blocked in the MST instance (MSTI) of the target MAC-based VLAN,
the port drops the received packets, instead of delivering them to the CPU. As a result, the receiving
port will not be dynamically assigned to the corresponding VLAN. Do not configure dynamic
MAC-based VLAN assignment together with MSTP, because the former is mainly configured on the
access side.
When PVST is enabled, if the VLAN to which a port is to be assigned is not allowed by the port, the
port is blocked. In this case, the port drops received packets instead of delivering them to the CPU,
failing to complete dynamic MAC-based VLAN assignment. Do not configure dynamic MAC-based
VLAN assignment together with PVST, because the former is mainly configured on the access side.
Configuration procedure
To configure static MAC-based VLAN assignment: