Configuring Port-Based and Client-Based Access Control (802.1X)

802.1X Open VLAN Mode

Table 8-1. 802.1X Open VLAN Mode Options

802.1X Per-Port Configuration

Port Response

 

 

Open VLAN Mode with Only an Authorized-Client VLAN Configured:

Port automatically blocks a client that cannot initiate an authentication session.

If the client successfully completes an authentication session, the port becomes an untagged member of this VLAN.

Note: if RADIUS authentication assigns a VLAN, the port temporarily becomes an untagged member of the RADIUS- assigned VLAN —instead of the Authorized-Client VLAN—while the client is connected.

If the port is statically configured as a tagged member of any other VLAN, the port returns to tagged membership in this VLAN upon successful client authentication. This happens even if the RADIUS server assigns the port to another, authorized VLAN. If the port is already configured as a tagged member of a VLAN that RADIUS assigns as an authorized VLAN, then the port becomes an untagged member of that VLAN for the duration of the client connection. After the client disconnects, the port returns to tagged membership in that VLAN.

Operating Rules for Authorized-Client and

Unauthorized-Client VLANs

ConditionRule

 

 

Static VLANs used as Authorized- These must be configured on the switch before you configure an Client or Unauthorized-ClientVLANs 802.1X authenticator port to use them. (Use the vlan < vlan-id>

command or the VLAN Menu screen in the Menu interface.)

VLAN Assignment Received from a RADIUS Server

If the RADIUS server specifies a VLAN for an authenticated supplicant connected to an 802.1X authenticator port, this VLAN assignment overrides any Authorized-Client VLAN assignment configured on the authenticator port. This is because both VLANs are untagged, and the switch allows only one untagged VLAN membership per-port. For example, suppose you configured port A4 to place authenticated supplicants in VLAN 20. If a RADIUS server authenticates supplicant “A” and assigns this supplicant to VLAN 50, then the port can access VLAN 50 as an untagged member while the client session is running. When the client disconnects from the port, then the port drops these assignments and uses the untagged VLAN memberships for which it is statically configured. (After client authentication, the port resumes any tagged VLAN memberships for which it is already configured. For details, refer to the Note on page 8-28.)

8-31