HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 106

undo dot1x critical vlan, display mac-vlan, dot1x, port-method, dot1x critical recovery-action

Page 106 highlights

View undo dot1x critical vlan Layer 2 Ethernet interface view Default level 2: System level Parameters vlan-id: Specifies a VLAN ID, in the range of 1 to 4094. Make sure the VLAN has been created. Description Use dot1x critical vlan to configure an 802.1X critical VLAN on a port for 802.1X users that have failed authentication because all the RADIUS authentication servers in their ISP domain are unreachable. Use undo dot1x critical vlan to restore the default. By default, no 802.1X critical VLAN is configured on a port. The 802.1X critical VLAN configuration applies to 802.1X users that use only RADIUS authentication servers and have failed authentication because all the servers in their ISP domain become unavailable (inactive), for example, for the loss of network connectivity. If an 802.1X user fails local authentication after RADIUS authentication, the user is not assigned to the critical VLAN. You can configure only one 802.1X critical VLAN on a port. The 802.1X critical VLANs on different ports can be different. Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X critical VLAN on a port, so the port can correctly process VLAN tagged incoming traffic. To have the 802.1X critical VLAN take effect, complete the following tasks: • Enable 802.1X both globally and on the interface. • If the port performs port-based access control, enable the 802.1X multicast trigger function. • If the port performs MAC-based access control, configure the MAC-based VLAN function on the port. When you change the access control method from MAC-based to port-based on the port, the mappings between MAC addresses and the 802.1X critical VLAN are removed. You can use the display mac-vlan command to display MAC-to-VLAN mappings. When you change the access control method from port-based to MAC-based on a port that is in a critical VLAN, the port is removed from the critical VLAN. To delete a VLAN that has been configured as an 802.1X critical VLAN, you must remove the 802.1X critical VLAN configuration first. Related commands: dot1x, dot1x port-method, and dot1x critical recovery-action. Examples # Specify VLAN 3 as the 802.1X critical VLAN for port GigabitEthernet 1/0/1. system-view [Sysname] interface gigabitethernet 1/0/1 [Sysname-GigabitEthernet1/0/1] dot1x critical vlan 3 97

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

97
undo dot1x critical vlan
View
Layer 2 Ethernet interface view
Default level
2: System level
Parameters
vlan-id
: Specifies a VLAN ID, in the range of 1 to 4094. Make sure the VLAN has been created.
Description
Use
dot1x critical vlan
to configure an 802.1X critical VLAN on a port for 802.1X users that have failed
authentication because all the RADIUS authentication servers in their ISP domain are unreachable.
Use
undo dot1x critical vlan
to restore the default.
By default, no 802.1X critical VLAN is configured on a port.
The 802.1X critical VLAN configuration applies to 802.1X users that use only RADIUS authentication
servers and have failed authentication because all the servers in their ISP domain become unavailable
(inactive), for example, for the loss of network connectivity. If an 802.1X user fails local authentication
after RADIUS authentication, the user is not assigned to the critical VLAN.
You can configure only one 802.1X critical VLAN on a port. The 802.1X critical VLANs on different ports
can be different.
Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X critical VLAN on a port, so the
port can correctly process VLAN tagged incoming traffic.
To have the 802.1X critical VLAN take effect, complete the following tasks:
Enable 802.1X both globally and on the interface.
If the port performs port-based access control, enable the 802.1X multicast trigger function.
If the port performs MAC-based access control, configure the MAC-based VLAN function on the
port.
When you change the access control method from MAC-based to port-based on the port, the mappings
between MAC addresses and the 802.1X critical VLAN are removed. You can use the
display mac-vlan
command to display MAC-to-VLAN mappings.
When you change the access control method from port-based to MAC-based on a port that is in a critical
VLAN, the port is removed from the critical VLAN.
To delete a VLAN that has been configured as an 802.1X critical VLAN, you must remove the 802.1X
critical VLAN configuration first.
Related commands:
dot1x
,
dot1x
port-method
, and
dot1x critical recovery-action
.
Examples
# Specify VLAN 3 as the 802.1X critical VLAN for port GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] dot1x critical vlan 3