beautypg.com

Example 2 -- multi-device, Port authentication with dynamic vlan assignment – Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 283

background image

mac-authentication auth-fail-action restrict-vlan

mac-authentication enable-dynamic-vlan

mac-authentication disable-ingress-filtering

The mac-authentication disable-ingress-filtering command enables tagged packets on the port,
even if the port is not a member of the VLAN. If this feature is not enabled, authentication works as in

Example 2 -- multi-device port authentication with dynamic VLAN assignment

on page 283

Example 2 -- multi-device port authentication with dynamic VLAN assignment

The following figure illustrates multi-device port authentication with dynamic VLAN assignment on a
Brocade device. In this configuration, a PC and an IP phone are connected to a hub, which is
connected to port e1 on a Brocade device. Port e1 is configured as a dual-mode port. The profile for the
PC MAC address on the RADIUS server specifies that the PC should be dynamically assigned to VLAN
102, and the RADIUS profile for the IP phone specifies that it should be dynamically assigned to VLAN
3.

Example 2 -- multi-device port authentication with dynamic VLAN assignment

FastIron Ethernet Switch Security Configuration Guide

283

53-1003088-03