Use Models for 802.1X Open VLAN Modes
-
Unauthorized-Client VLAN: Configure this VLAN when unauthenticated, friendly clients will need access to some services before being authenticated or instead of being authenticated.
-
Authorized-Client VLAN: Configure this VLAN for authenticated clients when the port is not statically configured as an untagged member of a VLAN you want clients to use, or when the port is statically configured as an untagged member of a VLAN you do not want clients to use. (A port can be configured as untagged on only one port-based VLAN. When an Authorized-Client VLAN is configured, it will always be untagged and will block the port from using a statically configured, untagged membership in another VLAN.) Note that after client authentication, the port returns to membership in any tagged VLANs for which it is configured.
802.1X Per-Port Configuration |
Port Response |
---|---|
No Open VLAN mode: |
The port automatically blocks a client that cannot initiate an authentication session. |
Open VLAN mode with both of the following configured: |
|
Unauthorized-Client VLAN |
|
Note for a Port Configured To Allow Multiple Client Sessions: If any previously authenticated clients are using a port assigned to a VLAN other than the Unauthorized-Client VLAN, then a later client that is not running 802.1X supplicant software is blocked on the port until all other, authenticated clients on the port have disconnected. |
|
Authorized-Client VLAN |
|
Open VLAN Mode with Only an Unauthorized-Client VLAN Configured: |
|
Open VLAN Mode with Only an Authorized-Client VLAN Configured |
Port automatically blocks a client that cannot initiate an authentication session. |
f the client successfully completes an authentication session, the port becomes an untagged member of this VLAN. |
|
If the port is statically configured as a tagged member of any other VLAN, the port returns to tagged membership in this VLAN upon successful client authentication. This happens even if the RADIUS server assigns the port to another, authorized VLAN. If the port is already configured as a tagged member of a VLAN that RADIUS assigns as an authorized VLAN, then the port becomes an untagged member of that VLAN for the duration of the client connection.
NOTE:
An authorized-client VLAN configuration can be overridden by a RADIUS authentication that assigns a VLAN. |