02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

If <strong>the</strong> supplicant fails au<strong>the</strong>ntication, <strong>the</strong> au<strong>the</strong>nticator typically does not enable <strong>the</strong> port. In some cases this<br />

behavior is not appropriate. External users of an enterprise network, <strong>for</strong> example, might not be able to be<br />

au<strong>the</strong>nticated, but still need access to <strong>the</strong> network. Also, some dumb-terminals such as network printers do<br />

not have 802.1X capability and <strong>the</strong>re<strong>for</strong>e cannot au<strong>the</strong>nticate <strong>the</strong>mselves. To be able to connect such<br />

devices, <strong>the</strong>y must be allowed access <strong>the</strong> network without compromising network security.<br />

The Guest VLAN 802.1X extension addresses this limitation with regard to non-802.1X capable devices,<br />

and <strong>the</strong> Au<strong>the</strong>ntication-fail VLAN 802.1X extension addresses this limitaion with regard to external users.<br />

• If <strong>the</strong> supplicant fails au<strong>the</strong>ntication a specified number of times, <strong>the</strong> au<strong>the</strong>nticator places <strong>the</strong> port in<br />

<strong>the</strong> Au<strong>the</strong>ntication-fail VLAN.<br />

• If a port is already <strong>for</strong>warding on <strong>the</strong> Guest VLAN when 802.1X is enabled, <strong>the</strong>n <strong>the</strong> port is moved out<br />

of <strong>the</strong> Guest VLAN, and <strong>the</strong> au<strong>the</strong>ntication process begins.<br />

Configuring a Guest VLAN<br />

If <strong>the</strong> supplicant does not respond within a determined amount of time ([reauth-max + 1] * tx-period, see<br />

Configuring Timeouts on page 683) <strong>the</strong> system assumes that <strong>the</strong> host does not have 802.1X capability, and<br />

and <strong>the</strong> port is placed in <strong>the</strong> Guest VLAN.<br />

Configure a port to be placed in <strong>the</strong> Guest VLAN after failing to respond within <strong>the</strong> timeout period using<br />

<strong>the</strong> command dot1x guest-vlan from INTERFACE mode, as shown in Figure 484.<br />

Figure 484 Configuring a Guest VLAN<br />

<strong>Force10</strong>(conf-if-gi-1/2)#dot1x guest-vlan 200<br />

<strong>Force10</strong>(conf-if-gi-1/2)#show config<br />

!<br />

interface GigabitE<strong>the</strong>rnet 1/2<br />

switchport<br />

dot1x guest-vlan 200<br />

no shutdown<br />

<strong>Force10</strong>(conf-if-gi-1/2)#<br />

View your configuration using <strong>the</strong> command show config from INTERFACE mode, as shown in<br />

Figure 484, or using <strong>the</strong> command show dot1x interface command from EXEC Privilege mode as shown<br />

in Figure 486.<br />

Configuring an Au<strong>the</strong>ntication-fail VLAN<br />

If <strong>the</strong> supplicant fails au<strong>the</strong>ntication, <strong>the</strong> au<strong>the</strong>nticator re-attempts to a<strong>the</strong>nticate after a specified amount of<br />

time (30 seconds by default, see Configuring a Quiet Period after a Failed Au<strong>the</strong>ntication on page 679).<br />

You can configure <strong>the</strong> maximum number of times <strong>the</strong> au<strong>the</strong>nticator re-attempts au<strong>the</strong>ntication after a<br />

failure (3 by default), after which <strong>the</strong> port is placed in <strong>the</strong> Au<strong>the</strong>ntication-fail VLAN.<br />

Configure a port to be placed in <strong>the</strong> VLAN after failing <strong>the</strong> au<strong>the</strong>ntication process as specified number of<br />

times using <strong>the</strong> command dot1x auth-fail-vlan from INTERFACE mode, as shown in Figure 485.<br />

Configure <strong>the</strong> maximum number of au<strong>the</strong>ntication attempts by <strong>the</strong> au<strong>the</strong>nticator using <strong>the</strong> keyword<br />

max-attempts with this command.<br />

686 802.1X

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!