Authentication Failure Scenarios
VLAN assignment in authentication failure cases depends on the authentication mode of the port being single untagged mode (the default) or multiple untagged mode. The authentication failure action configured applies to MAC authentication and 802.1X authentication and can be one of the following actions:
A failure action of moving the client to a restricted VLAN works only if the RADIUS server sends an Access-Reject message. Any other failure, for example, an undefined ACL or a VLAN movement error, results in blocking the client's MAC address.
A default ACL with IPv4 or IPv6 filters can also be configured to apply, if the failure action is a restricted VLAN.
An authentication failure action of blocking blocks the clients in both single and multiple untagged mode. If the authentication failure action is to move to a restricted VLAN, the behavior depends on whether the authentication mode is single untagged mode or multiple untagged mode.
In single untagged mode, the following behaviors apply:
- If the first client's authentication fails, the port membership is moved from the auth-default VLAN to the restricted VLAN.
- If other clients were authenticated previously on the same port, the new client is always blocked. Even after all other clients age out, the new client remains in the VLAN reserved for blocked clients until it ages out.
- If the previous sessions are in a restricted VLAN, the new client is moved to the restricted VLAN.
- If the previous sessions are in the critical VLAN or guest VLAN, the new client is blocked.
- In MAC authentication, if the authentication is initiated by a tagged packet, the client is blocked in the tagged VLAN irrespective of the configured failure action.
In multiple untagged mode, the following behaviors apply:
- If the failure action is configured as a restricted VLAN, the client is moved to the restricted VLAN. If the port is not part of the restricted VLAN, the port is made a MAC-VLAN member of the restricted VLAN.
- For MAC authentication, if the authentication is initiated by a tagged packet, the client is blocked in the tagged VLAN irrespective of the configured failure action.