Dell PowerEdge M420 Dell PowerConnect M8024-k Release Notes - Page 17

Dynamic VLAN Assignment, Usability Enhancements, Simple Mode, AAA Authentication

Page 17 highlights

PowerConnect M6220/M6348/8024/8024F/M8024/M8024-k/ 7024/7048/7024P/7048P/7024F/7048R/7048R-RA Release Notes  Dynamic VLAN Assignment Dynamic VLAN assignment is intended to support the connection of hosts to a router with enhanced levels of service, typically either security or QoS. This release supports dynamic VLAN assignment as assigned from the RADIUS server as part of port authentication. The following additional checks are performed in support of dynamic VLAN assignment: Before assigning the port to RADIUS assigned VLAN, dot1x checks if the given VLAN is in the VLAN database or not. If the assigned VLAN is not in the VLAN database and dynamic VLAN assignment is enabled, a VLAN is created on the port over which the client is authenticated. Each time a client is de-authenticated on an interface with a particular VLAN, a check verifies if there any other interface which is a VLAN member. If there is no interface as a member, the VLAN is deleted. This behavior is same for MAC based authentication as well.  Usability Enhancements In the output of the show running-config command, the slot and member configuration is commented with the switch/slot type in human comprehensible form. When in interface config mode, CLI users can navigate to a different interface by entering the appropriate interface command without leaving interface config mode. CLI users can log out of the switch using the exit command (exit is an alias for quit). The CLI Reference Guide is updated with acceptable character sets and maximum lengths for string parameters to commands. Management ACLs permit specification of service any as shorthand for enabling all services access for in-band management. VLANs may be administratively assigned to MSTIs in excess of the switch physical limits and without regard to whether the VLAN is actually configured. Frames are only forwarded on VLANs assigned to interfaces. Administrators can re-enter SYSLOG server config mode for a particular SYSLOG server entry without requiring the deletion and re-creation of the entry. Administrators can configure the web timeout by navigating to: System -> Management Security -> Telnet Server -> Telnet Session Timeout. User configured banners (login, exec, MOTD) appear in the running config. By default, auto-install supports image downgrade for network installs, specific version USB installs (using a .setup file), and stack firmware synchronization. A comprehensible message and recommendation is issued when configuring multiple services (telnet, http,...) to listen on the same TCP port. The terminal length command allows user control over terminal paging.  Simple Mode The PowerConnect M8024-k is the only modular switch that defaults to the simple mode of operation. Simple mode contains a restricted set of commands suitable for control of a port aggregation device that can be deployed in a network without requiring updates to the network by a network administrator. Users needing switch capabilities which require the network administrator to modify the network configuration can exit simple mode using the no mode simple command.  AAA Authentication In prior releases, more than one method could be specified for dot1x authentication even though only the first method was attempted. The CLI and Web now only accept a single method for dot1x authentication. System Firmware Version 4.1.0.6 Page 15

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27

PowerConnect M6220/M6348/8024/8024F/M8024/M8024-k/
7024/7048/7024P/7048P/7024F/7048R/7048R-RA Release Notes
System Firmware Version 4.1.0.6
Page 15
Dynamic VLAN Assignment
Dynamic VLAN assignment is intended to support the connection of hosts to a router with enhanced levels of service,
typically either security or QoS. This release supports dynamic VLAN assignment as assigned from the RADIUS
server as part of port authentication. The following additional checks are performed in support of dynamic VLAN
assignment:
Before assigning the port to RADIUS assigned VLAN, dot1x checks if the given VLAN is in the VLAN database or
not. If the assigned VLAN is not in the VLAN database and dynamic VLAN assignment is enabled, a VLAN is created
on the port over which the client is authenticated. Each time a client is de-authenticated on an interface with a particular
VLAN, a check verifies if there any other interface which is a VLAN member. If there is no interface as a member, the
VLAN is deleted. This behavior is same for MAC based authentication as well.
Usability Enhancements
In the output of the
show running-config
command, the slot and member configuration is commented with the
switch/slot type in human comprehensible form.
When in interface config mode, CLI users can navigate to a different interface by entering the appropriate interface
command without leaving interface config mode.
CLI users can log out of the switch using the
exit
command (
exit
is an alias for
quit
).
The CLI Reference Guide is updated with acceptable character sets and maximum lengths for string parameters to
commands.
Management ACLs permit specification of
service any
as shorthand for enabling all services access for in-band
management.
VLANs may be administratively assigned to MSTIs in excess of the switch physical limits and without regard to
whether the VLAN is actually configured. Frames are only forwarded on VLANs assigned to interfaces.
Administrators can re-enter SYSLOG server config mode for a particular SYSLOG server entry without requiring the
deletion and re-creation of the entry.
Administrators can configure the web timeout by navigating to: System -> Management Security -> Telnet Server ->
Telnet Session Timeout.
User configured banners (login, exec, MOTD) appear in the running config.
By default, auto-install supports image downgrade for network installs, specific version USB installs (using a .setup
file), and stack firmware synchronization.
A comprehensible message and recommendation is
issued when configuring multiple services (telnet, http,…) to listen
on the same TCP port.
The
terminal length
command allows user control over terminal paging.
Simple Mode
The PowerConnect M8024-k is the only modular switch that defaults to the simple mode of operation. Simple mode
contains a restricted set of commands suitable for control of a port aggregation device that can be deployed in a
network without requiring updates to the network by a network administrator. Users needing switch capabilities which
require the network administrator to modify the network configuration can exit simple mode using the
no mode simple
command.
AAA Authentication
In prior releases, more than one method could be specified for dot1x authentication even though only the first method
was attempted. The CLI and Web now only accept a single method for dot1x authentication.