Configuration Considerations and Guidelines for Flexible Authentication
- In Flexible authentication, ICX 8200 switches require a Layer 2 ingress ACL per user in multiple-untagged mode. The user will be blocked if the ACL filter is not installed due to hardware resources.
- In FastIron 08.0.90 and later releases, there will no longer be any link flap when a port is being added as a tagged member to a VLAN for the first time or when a port is being removed from the last tagged VLAN. External devices that may have relied on this link flap in the past for any kind of renegotiation must be reconfigured appropriately, or you must manually flap the interface.
- The RADIUS server must be configured to support a specific authentication method or a combination of authentication methods. A RADIUS server can be configured to use only 802.1X authentication, MAC authentication, Web authentication, or a combination of these authentication methods. However, from FastIron release 09.0.10b, any RADIUS server configured at the interface level will work for both 802.1x and Mac auth authentication methods, no matter what authentication methods are configured globally. For more information about RADIUS configuration, refer to RADIUS Authentication.
- Avoid configuring both secure and non-secure RADIUS servers in the same RUCKUS ICX network. For example, avoid using both UDP and TLS connections to RADIUS servers from an ICX switch configuration.
- MACsec and Flexible authentication cannot be configured on the same port.
- Flexible authentication and MVRP cannot be enabled on the same port.
- MVRP dynamic VLANs cannot be configured as authentication VLANs (auth-default VLAN, guest VLAN, critical VLAN, or restricted VLAN). This limitation applies at both the global configuration and interface configuration levels.
- Flexible authentication cannot be enabled on ports that have any of the following features enabled:
- Incoming traffic on unauthenticated ports is blocked by ICX devices, while allowing for outgoing broadcasts and multicasts to account for waking connected devices that are in a sleep state. This is the default behavior, and there is no configuration option.
- Once a VLAN is assigned as an authentication special VLAN (a critical VLAN, voice VLAN, guest VLAN, or restricted VLAN), it is not advisable to delete the VLAN. If the VLAN is deleted, you must take care of global authentication changes and impact.
- It is not advisable to assign a non-existent VLAN as an authentication special VLAN, particularly at the interface level.
- If Web authentication is enabled on the restricted VLAN, critical VLAN, guest VLAN, or a RADIUS-assigned VLAN, the device uses Web authentication as a fallback or additional authentication method. Web authentication can be enabled on eight VLANs.
- When
authentication allow-tagged enablecommand is enabled, the IEEE 802.1x client must ensure that it sends tagged traffic which is returned by RADIUS VLAN. If the client sends traffic with a VLAN that is not allowed or blocked, the traffic will be forwarded to the CPU, resulting in high CPU usage.
- The client session establishes a relationship between the username and MAC address used for authentication. If attempting to gain access from different clients (with different MAC addresses), you must be authenticated from each client.
- When a client is denied access to the network, its session is aged out if no traffic is received from the client MAC address over a default hardware aging period (70 seconds), plus a software aging period. Both these age intervals can be changed, or session aging can be disabled altogether. After the denied client session is aged out, traffic from that client is no longer blocked, and the client can be reauthenticated.
- In the
authentication filtercommand used to configure authentication override for specified MAC addresses, the statements permit any any and deny any any are not allowed. - When dox1x port-control is configured as "force-authorized" or "force-unauthorized" on an interface, interface authentication configuration is not allowed on that interface.
- When Flex Auth is configured on a Multi-Chassis Trunking (MCT) Cluster Edge Port (CEP) that has a previously configured MCT VLAN, the dynamic VLAN returned for the user by RADIUS must be the same as the MCT VLAN.
- RADIUS attributes such as VLAN or ACL assignments cannot be changed dynamically in the RADIUS server when a Flexible authentication session is already authenticated. Likewise, a VLAN or ACL cannot be changed when an authenticated client reauthenticates. To apply an updated attribute, the related session must be cleared manually, and the attribute must be modified in the RADIUS server before the client is authenticated.