73
Using the Business Policy Switch 2000 Version 1.2
The Authenticator determines the controll ed port’s operational state. After the
RADIUS server notifies the Authenticator PAE about the success or failure of the
authentication, it changes the controlled port’s operational state accordingly.
The Authenticator PAE functionality is implemented for each c ontrolled port on
the switch. At system initialization, or when a supplicant is initially connected to
the switch’s controlled port, the controlled port’s state is set to Blocking. During
that time, EAP packets are processed by the authenticator.
When the Authentication server returns a “success” or “failure” message, the
controlled port’s state is changed accordingly. If the authorization is successful,
the controlled port’s operational state is set to Forwarding. Otherwise, the
controlled port’s state depends on the Operational Traffic Control field value in
the EAPOL Security Configuration screen.
The Operational Traffic Control field can have one of the following two values:
•Incoming and Outgoing—If the controlled port is unauthorized, frames are
not transmitted through the port; all frames received on the controlled port are
discarded. The controlled port’s state is set to Blocking.
•Incoming—If the controlled port is unauthorized, frames received on the port
are discarded, but the transmit frames are forwarded through the port.
EAPOL dynamic VLAN assignmentIf EAPOL-based security is enabled on a port, and then the port is authorized, the
EAPOL feature dynamically changes the port’s VLAN configurati on accordi ng to
preconfigured values, and assigns a new VLAN. The new VLAN configuration
values are applied according to previously stored parameters (based on the
user_id) in the Authentication server.
The following VLAN configuration values are affected:
•Port membership
•PVID
•Port priority