HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 99

Configuring an 802.1X critical VLAN, Configuration guidelines, Configuration prerequisites,

Page 99 highlights

Step Command Remarks 1. Enter system view. system-view N/A 2. Enter Ethernet interface view. interface interface-type interface-number N/A 3. Configure the Auth-Fail VLAN on the port. dot1x auth-fail vlan authfail-vlan-id By default, no Auth-Fail VLAN is configured. Configuring an 802.1X critical VLAN Configuration guidelines • Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X critical VLAN on a port, so the port can correctly process VLAN tagged incoming traffic. • You can configure only one 802.1X critical VLAN on a port. The 802.1X critical VLANs on different ports can be different. • When the port moves between VLANs (for example, leaves the 802.1X guest VLAN and joins the critical VLAN), ask 802.1X users to manually update their IP address so that they can access specific resources. Configuration prerequisites • Create the VLAN to be specified as a critical VLAN. • If the 802.1X-enabled port performs port-based access control, enable 802.1X multicast trigger (dot1x multicast-trigger). • If the 802.1X-enabled port performs MAC-based access control, configure the port as a hybrid port, enable MAC-based VLAN on the port, and assign the port to the Auth-Fail VLAN as an untagged member. For more information about the MAC-based VLAN function, see Layer 2-LAN Switching Configuration Guide. Configuration procedure To configure an 802.1X critical VLAN: Step 1. Enter system view. 2. Enter Layer 2 Ethernet interface view. 3. Configure an 802.1X critical VLAN on the port. Command system-view interface interface-type interface-number dot1x critical vlan vlan-id 4. Configure the port to trigger 802.1X authentication on detection of a reachable authentication server for users dot1x critical recovery-action reinitialize in the critical VLAN. Remarks N/A N/A By default, no critical VLAN is configured. Optional. By default, when a reachable RADIUS server is detected, the system removes the port or 802.1X users from the critical VLAN without triggering authentication. 89

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

89
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Ethernet interface view.
interface
interface-type
interface-number
N/A
3.
Configure the Auth-Fail VLAN
on the port.
dot1x auth-fail vlan
authfail-vlan-id
By default, no Auth-Fail VLAN is
configured.
Configuring an 802.1X critical VLAN
Configuration guidelines
Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X critical VLAN on a port, so
the port can correctly process VLAN tagged incoming traffic.
You can configure only one 802.1X critical VLAN on a port. The 802.1X critical VLANs on different
ports can be different.
When the port moves between VLANs (for example, leaves the 802.1X guest VLAN and joins the
critical VLAN), ask 802.1X users to manually update their IP address so that they can access
specific resources.
Configuration prerequisites
Create the VLAN to be specified as a critical VLAN.
If the 802.1X-enabled port performs port-based access control, enable 802.1X multicast trigger
(
dot1x multicast-trigger
).
If the 802.1X-enabled port performs MAC-based access control, configure the port as a hybrid port,
enable MAC-based VLAN on the port, and assign the port to the Auth-Fail VLAN as an untagged
member. For more information about the MAC-based VLAN function, see
Layer 2
LAN Switching
Configuration Guide
.
Configuration procedure
To configure an 802.1X critical VLAN:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
3.
Configure an 802.1X critical
VLAN on the port.
dot1x critical vlan
vlan-id
By default, no critical VLAN is
configured.
4.
Configure the port to trigger
802.1X authentication on
detection of a reachable
authentication server for users
in the critical VLAN.
dot1x critical recovery-action
reinitialize
Optional.
By default, when a reachable
RADIUS server is detected, the
system removes the port or 802.1X
users from the critical VLAN
without triggering authentication.