40-17
Software Configuration Guide—Release 15.0(2)SG
OL-23818-01
Chapter 40 Configuring 802.1X Port-Based Authentication About 802.1X Port-Based Authentication

Deployment Example

In a large campus LAN design, you might want to design the VLAN infrastructure without large Layer
2 domain. For the same employee VLAN, customers might have different VLANs at different campus
access switches. When you deploy 802.1X with VLAN assignment, it does not assign one employee
VLAN to all employees. You have to know the real VLANs configured on the switch. User distribution
allows you to send a list of VLAN or VLAN group name(s) to the switch. Your switch can then do a local
mapping to the corresponding VLAN. (Figure 40-7).
Figure 40-7 802.1X with VLAN User Distribution
For details on how to configure VLAN User Distribution, see the “Configuring 802.1X with VLAN User
Distribution” section on page 40-65.
Using 802.1X with Authentication Failed VLAN Assignment
You can use authentication-failed VLAN assignment on a per-port basis to provide access for
authentication failed users. Authentication failed users are end hosts that are 802.1X- capable but do not
have valid credentials in an authentication server or end hosts that do not give any username and
password combination in the authentication pop-up window on the user side.
If a user fails the authentication process, that port is placed in the authentication-failed VLAN. The port
remains in the authentication-failed VLAN until the reauthentication timer expires. When the
reauthentication timer expires the switch starts sending the port reauthentication requests. If the port
fails reauthentication it remains in the authentication-failed VLAN. If the port is successfully
reauthenticated, the port is moved either to the VLAN sent by RADIUS server or to the newly
authenticated ports configured VLAN; the location depends on whether RADIUS is configured to send
VLAN information.
Note When enabling periodic reauthentication (see the “Enabling Periodic Reauthentication” section on
page 40-78), only local reauthentication timer values are allowed. You cannot use a RADIUS server to
assign the reauthentication timer value.