Authentication Success Scenarios
The dynamic VLAN assignment depends on the various VLAN formats returned by the RADIUS server.
RADIUS Returns Only a VLAN Identifier or an Untagged VLAN Identifier
When the Access-Accept message returned by RADIUS contains the VLAN information in either vlan-id or vlan-name or U:vlan-id or U:vlan-name format:
In single untagged mode (the default), the port membership is removed from the auth-default VLAN and added to the RADIUS-specified VLAN as a MAC-VLAN member.
The following behavior is the default behavior of the device:
- Subsequent clients that are authenticated with different dynamic VLANs are blocked.
- If another client is authenticated on the same VLAN, it is permitted in the first client's dynamic VLAN.
- If another client is authenticated on the port without a RADIUS VLAN, it is permitted in the first client's dynamic VLAN.
- Once all the clients in the new VLAN age out, the port is moved back to the auth-default VLAN.
- In multiple untagged mode, the port is added as a MAC-VLAN member to the RADIUS-specified VLAN without removing its membership from the auth-default VLAN.
RADIUS Returns a Single or Multiple Tagged VLAN Identifiers
When the Access-Accept message returned by RADIUS contains the VLAN information in either T:vlan-id or T:vlan-id1; T:vlan-id2 format, for MAC authentication, if the authentication is triggered by a tagged packet and if the VLAN matches the tagged VLAN or VLAN list returned by RADIUS, the session is authenticated, and the port becomes a tagged member of all the dynamically assigned VLANs.
RADIUS Returns Untagged and Single or Multiple Tagged VLAN Identifiers
When the Access-Accept message returned by RADIUS contains the VLAN information in U:vlan-id1; T:vlan-id2 or U:vlan-id1; T:vlan-id2; T:vlan-id3; T:vlan-id4 format:
In single untagged mode (the default), the port membership is removed from the auth-default VLAN and added to the RADIUS-specified VLAN as a MAC-VLAN member. It is also added to the tagged VLANs as a tagged member.
The following behavior is the default behavior of the device:
- Subsequent clients that are authenticated with different dynamic VLANs are blocked.
- If another client is authenticated on the same VLAN, it is permitted in the first client's dynamic VLAN.
- If another client is authenticated on the port without a RADIUS VLAN, it is permitted in the first client's dynamic VLAN.
- Once all the clients in the new VLAN age out, the port is moved back to the auth-default VLAN.
- In multiple untagged mode, the port is added as a MAC-VLAN member to the RADIUS-specified untagged VLAN without removing its membership from the auth-default VLAN. It is also added to the tagged VLANs as a tagged member.
For MAC authentication, if the authentication is triggered by a tagged packet and if the VLAN matches the tagged VLAN or VLAN list returned by RADIUS, the session is authenticated, and the port becomes an untagged member of one VLAN and a tagged member of the other dynamically assigned VLANs.