A SERVICE OF

logo

Configuring Port-Based and User-Based Access Control (802.1X)
General 802.1X Authenticator Operation
No
Yes
New Client
Authenticated
Untagged
VLAN
Configured
On Port ?
RADIUS-
Assigned
VLAN?
Authorized
VLAN
Configured?
Another
(Old) Client
Already Using
Port
?
Are All Old
Clients On
Unauthorized
VLAN?
No
No
Yes
Yes
Assign New Client
to RADIUS-
Specified VLAN
Assign New Client
to Authorized VLAN
Configured on Port
Assign New Client
to Untagged VLAN
Configured On Port
Yes
New
Client VLAN
Same As Old
Client VLAN?
No
Drop All Clients
Using Unauthorized
VLAN
No
Reject New Client
On Port
Yes
Accept New Client
On Port
Yes
No
Figure 12-1. Priority of VLAN Assignment for an Authenticated Client
12-11