Auth-Fail VLAN
The 802.1X Auth-Fail VLAN on a port accommodates users who have failed 802.1X authentication because of the failure to comply with the organization security strategy. For example, the VLAN accommodates users who have entered a wrong password. Users in the Auth-Fail VLAN can access a limited set of network resources, such as a software server, to download antivirus software and system patches.
The Auth-Fail VLAN does not accommodate 802.1X users who have failed authentication for authentication timeouts or network connection problems.
The access device handles VLANs on an 802.1X-enabled port based on its 802.1X access control method.
On a port that performs port-based access control:
Authentication status | VLAN manipulation |
---|---|
A user fails 802.1X authentication. | The device assigns the Auth-Fail VLAN to the port as the PVID. All 802.1X users on this port can access only resources in the Auth-Fail VLAN. |
A user in the 802.1X Auth-Fail VLAN fails 802.1X authentication because of any other reason except for unreachable servers. | The Auth-Fail VLAN is still the PVID on the port, and all 802.1X users on this port are in this VLAN. |
A user passes 802.1X authentication. |
|
On a port that performs MAC-based access control:
Authentication status | VLAN manipulation |
---|---|
A user fails 802.1X authentication. | The device maps the MAC address of the user to the 802.1X Auth-Fail VLAN. The user can access only resources in the Auth-Fail VLAN. |
A user in the 802.1X Auth-Fail VLAN fails 802.1X authentication because of any other reason except for unreachable servers. | The user is still in the Auth-Fail VLAN. |
A user in the 802.1X Auth-Fail VLAN passes 802.1X authentication. | The device remaps the MAC address of the user to the authorization VLAN. If the authentication server does not authorize a VLAN, the device remaps the MAC address of the user to the initial PVID on the port. |
For the 802.1X Auth-Fail VLAN feature to take effect on a port that performs MAC-based access control, make sure the following requirements are met:
The port is a hybrid port.
MAC-based VLAN is enabled on the port.
The access device assigns a hybrid port to an 802.1X Auth-Fail VLAN as an untagged member.
For more information about VLAN configuration and MAC-based VLANs, see Layer 2—LAN Switching Configuration Guide. Support for the MAC-based VLAN feature depends on the device model.