beautypg.com

1x authentication with dynamic vlan assignment – Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 214

background image

device(config-if-e1000-1)#dot1x port-control auto

device(config-if-e1000-1)#exit

802.1X Authentication with dynamic VLAN assignment

The following figure illustrates 802.1X authentication with dynamic VLAN assignment. In this
configuration, two user PCs are connected to a hub, which is connected to port e2. Port e2 is
configured as a dual-mode port. Both PCs transmit untagged traffic. The profile for User 1 on the
RADIUS server specifies that User 1 PC should be dynamically assigned to VLAN 3. The RADIUS
profile for User 2 on the RADIUS server specifies that User 2 PC should be dynamically assigned to
VLAN 20.

FIGURE 8 Sample configuration using 802.1X authentication with dynamic VLAN assignment

In this example, the PVID for port e2 would be changed based on the first host to be successfully
authenticated. If User 1 is authenticated first, then the PVID for port e2 is changed to VLAN 3. If User

802.1X Authentication with dynamic VLAN assignment

214

FastIron Ethernet Switch Security Configuration Guide

53-1003088-03