Alcatel 9000 Guía de usuario Pagina 473

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 702
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 472
Configuring 802.1X Configuring Access Guardian Policies
OmniSwitch 6800/6850/9000 Network Configuration Guide June 2006 page 23-17
To configure a compound non-supplicant policy, use the pass and fail keywords to specify which policies
to apply when MAC authentication is successful but does not return a VLAN ID and which policies to
apply when MAC authentication fails. The pass keyword is implied and therefore an optional keyword. If
the fail keyword is not used, the default action is to block the device when authentication fails.
Note. When a policy is specified as a policy to apply when authentication fails, device classification is
restricted to assigning non-supplicant devices to VLANs that are not authenticated VLANs.
To configure a non-supplicant policy that will not perform MAC authentication, use the 802.1x non-
supplicant policy command. The following keywords are available with this command to specify one or
more policies for classifying devices
:
Note that this type of policy does not use 802.1x or MAC authentication. As a result, all of the available
policy keywords restrict the assignment of the non-supplicant device to only those VLANs that are non-
authenticated VLANs. The pass and fail keywords are not used when configuring this type of policy.
Non-supplicant Policy Examples
The following table provides example non-supplicant policy commands and a description of how the
resulting policy is applied to classify supplicant devices:
supplicant policy keywords
group mobility
vlan
default-vlan
block
Supplicant Policy Command Example Description
802.1x 1/24 non-supplicant policy authentication
pass group-mobility default-vlan fail vlan 10 block
If the MAC authentication process is successful
but does not return a VLAN ID for the device, then
the following occurs:
1 Group Mobility rules are applied.
2 If Group Mobility classification fails, then the
device is assigned to the default VLAN for
port 1/24.
If the device fails MAC authentication, then the
following occurs:
1 If VLAN 10 exists and is not an authenticated
VLAN, the device is assigned to VLAN 10.
2 If VLAN 10 does not exist or is an authenti-
cated VLAN, the device is blocked from
accessing the switch on port 1/24.
802.1x 1/48 non-supplicant policy authentication
vlan 10 default-vlan
If the MAC authentication process is successful
but does not return a VLAN ID for the device, then
the following occurs:
1 The device is assigned to VLAN 10.
2 If VLAN 10 does not exist, then the device is
assigned to the default VLAN for port 1/48.
If the device fails MAC authentication, the device
is blocked from accessing the switch on port 1/48.
Vista de pagina 472
1 2 ... 468 469 470 471 472 473 474 475 476 477 478 ... 701 702

Comentarios a estos manuales

Sin comentarios