Creating Authentication Profiles
Creating and managing authentication profiles defines how 802.1X and MAC-authentication actions are processed in the switch. This includes specifying actions for authentication failures and authentication timeout, and assigning VLANs for critical, guest, and restricted access scenarios.
Configure at least one authentication profile in the group for port-based authentication. Complete the following steps to create a authentication profile for the selected Switch Group.
- In the main menu, navigate to .The Switches page is displayed.
- In the Switches page, select the Switch Group that you want to configure, and scroll to the Details section.
- In the Details section, click the Configuration tab.
- In the Configuration tab, click Authentication Profiles.
- In the Authentication Profiles page, click Create to create a new profile or select an existing profile and click Next to edit it.
- Configure the following parameters.
- Profile Name: Provide a name for this profile.
- Type: Select one of the following options.
- Change Authentication Order: This option is available when the Type is selected as 802.1x and MAC-AUTH. By default, 802.1X authentication is processed first and the MAC authentication is only processed if the authentication server is not responding. Enable the toggle to change the authentication order and process MAC authentication first.
- 802.1X Port Control: This option is available
when the Type is selected as 802.1x.
Select one of the following options:
- Auto: The authorization state of the port depends on the response from the server. If the authentication server responds with an access-accept, then the port will be authorized, otherwise, it will remain unauthorized.
- Force Authorized: The ports will be in the authorized state skipping the authentication process.
- Force Unauthorized: The ports will be in an unauthorized state skipping the authentication process.
- Auth Default VLAN: All ports belong to this VLAN before any authentication process is started.
- Fail Action: Indicates what action to take if the authentication is denied.
- Timeout Action: Indicates what action to take if
the authentication does not respond to the authentication request.
Choose one of the following options:
- Critical VLAN: The port is placed in the critical VLAN. When you select this option, you must also specify the Restricted VLAN number.
- Success: Place the port in an authorized state and permit traffic.
- Failure: Place the port in an unauthorized state and any traffic is blocked.
- None: The authentication process keeps going indefinitely.
- Click OK.