73
Using the Business Policy Switch 2000 Version 1.2
The Authenticator determines the controll ed ports operational state. After the
RADIUS server notifies the Authenticator PAE about the success or failure of the
authentication, it changes the controlled ports operational state accordingly.
The Authenticator PAE functionality is implemented for each c ontrolled port on
the switch. At system initialization, or when a supplicant is initially connected to
the switchs controlled port, the controlled ports state is set to Blocking. During
that time, EAP packets are processed by the authenticator.
When the Authentication server returns a success or failure message, the
controlled ports state is changed accordingly. If the authorization is successful,
the controlled ports operational state is set to Forwarding. Otherwise, the
controlled ports state depends on the Operational Traffic Control field value in
the EAPOL Security Configuration screen.
The Operational Traffic Control field can have one of the following two values:
Incoming and OutgoingIf the controlled port is unauthorized, frames are
not transmitted through the port; all frames received on the controlled port are
discarded. The controlled ports state is set to Blocking.
IncomingIf the controlled port is unauthorized, frames received on the port
are discarded, but the transmit frames are forwarded through the port.
EAPOL dynamic VLAN assignment
If EAPOL-based security is enabled on a port, and then the port is authorized, the
EAPOL feature dynamically changes the ports VLAN configurati on accordi ng to
preconfigured values, and assigns a new VLAN. The new VLAN configuration
values are applied according to previously stored parameters (based on the
user_id) in the Authentication server.
The following VLAN configuration values are affected:
Port membership
PVID
Port priority