beautypg.com

Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 284

background image

FIGURE 11 Using multi-device port authentication with dynamic VLAN assignment

In this example, multi-device port authentication is performed for both devices. If the PC is
successfully authenticated, dual-mode port e1 PVID is changed from the VLAN 1 (the DEFAULT-
VLAN) to VLAN 102. If authentication for the PC fails, then the PC can be placed in a specified
"restricted" VLAN, or traffic from the PC can be blocked in hardware. In this example, if authentication
for the PC fails, the PC would be placed in VLAN 1023, the restricted VLAN.

If authentication for the IP phone is successful, then dual-mode port e1 is added to VLAN 3. If
authentication for the IP phone fails, then traffic from the IP phone would be blocked in hardware.
(Devices sending tagged traffic cannot be placed in the restricted VLAN.)

NOTE
This example assumes that the IP phone initially transmits untagged packets (for example, CDP or
DHCP packets), which trigger the authentication process on the Brocade device and client lookup on
the RADIUS server. If the phone sends only tagged packets and the port (e1) is not a member of that

Multi-Device Port Authentication

284

FastIron Ethernet Switch Security Configuration Guide

53-1003088-03