
Configuring 802.1X Configuring Access Guardian Policies
OmniSwitch 6800/6850/9000 Network Configuration Guide June 2006 page 23-15
Note that if no policies are configured on an 802.1x port, non-supplicants are blocked on the port and the
following classification process is performed for supplicants by default:
1 802.1x authentication via remote RADIUS server is attempted.
2 If authentication fails or successful authentication returns a VLAN ID that does not exist, the device is
blocked.
3 If authentication is successful and returns a VLAN ID that exists in the switch configuration, suppli-
cant is assigned to that VLAN.
4 If authentication is successful but does not return a VLAN ID, Group Mobility rules are checked for
classification.
5 If Group Mobility classification fails, the supplicant is assigned to the default VLAN ID for the 802.1x
port.
Configuring Supplicant Policies
Supplicant policies are used to classify 802.1x devices connected to 802.1x-enabled switch ports when
802.1x authentication does not return a VLAN ID or authentication fails. To configure supplicant poli-
cies, use the 802.1x supplicant policy authentication command. The following keywords are available
with this command to specify one or more policies for classifying devices:
If no policy keywords are specified with this command, then supplicants are blocked if 802.1x authentica-
tion fails or does not return a VLAN ID. When multiple policies are specified, the policy is referred to as a
compound supplicant policy. Note that the order in which parameters are configured determines the order
in which they are applied.
To configure a compound supplicant policy, use the pass and fail keywords to specify which policies to
apply when 802.1x authentication is successful but does not return a VLAN ID and which policies to
apply when 802.1x authentication fails or returns a VLAN ID that does not exist. The pass keyword is
implied and therefore an optional keyword. If the fail keyword is not used, the default action is to block
the device.
Note. When a policy is specified as a policy to apply when authentication fails, device classification is
restricted to assigning supplicant devices to VLANs that are not authenticated VLANs.
supplicant policy keywords
group mobility
vlan
default-vlan
block
pass
fail
Kommentare zu diesen Handbüchern