Data VLAN Requirements for Flexible Authentication
Before authentication is enabled on a port, the port can belong to any VLAN, including the system default VLAN. The only restriction is that the port cannot be a part of any VLAN as untagged. After authentication is enabled on that port, the port becomes a part of the auth-default VLAN. When a VLAN is assigned after successful authentication, it is assigned to the client (to the MAC address of the client), not to the entire port. In reality, however, the port is added to the VLAN as a MAC-VLAN member.
When authentication succeeds, the client is moved to the VLAN returned by the RADIUS server. When the RADIUS authentication fails or the RADIUS server is unavailable, the client is moved to the restricted VLAN or critical VLAN.
You can also configure specific VLANs to associate the clients in various success, failure, and timeout scenarios. The following scenarios and options are available to place the client in various VLANs depending on the authentication status:
- Auth-default VLAN: A VLAN must be configured as the auth-default VLAN to enable Flexible
authentication. When any port is enabled for 802.1X authentication or MAC authentication,
the client is moved to this VLAN by default. The auth-default VLAN is also used in
the following scenarios:
- When the RADIUS server does not return any VLAN information upon authentication, the client is authenticated and remains in the auth-default VLAN.
- If RADIUS timeout occurs during the first authentication and the timeout action is configured as "success", the client is authenticated in the auth-default VLAN. If the RADIUS server is not available during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN.
- If authentication fails and the fail action is configured as "permit", the attempt is logged as a failure but treated as a successful authentication, and the cleint is placed in the auth-default VLAN.
- Restricted VLAN: When an authentication fails, the port can be moved into a restricted
VLAN instead of blocking the client completely. The port is moved to the configured
restricted VLAN only if the authentication failure action is configured to place the
port in a restricted VLAN using the
auth-fail-actioncommand in the authentication configuration mode. Otherwise, when the authentication fails, the client's MAC address is blocked in the hardware, which is the default action. A restricted VLAN can be configured using therestricted-vlancommand in the authentication configuration mode.
- Critical VLAN: There may be times when the RADIUS server times out or is not available,
resulting in timeout. This can happen the first time the client is authenticating
or when the client reauthenticates. In such scenarios, if the authentication timeout
action is specified as a critical VLAN using the
authentication timeout-actioncommand in the authentication configuration mode, the client is moved to the specified critical VLAN. A critical VLAN can be configured using thecritical-vlancommand in the authentication configuration mode.
- Guest VLAN: The guest VLAN is used when a client does not respond to dot1x requests for authentication. It is possible that the client does not support or have the dot1x supplicant loaded. In such a scenario, the client is moved to the guest VLAN to have access to the network with default privileges. From the guest VLAN, the client can download the supplicant.