Authentication Success Scenarios

The dynamic VLAN assignment depends on the various VLAN formats returned by the RADIUS server.

RADIUS Returns Only a VLAN Identifier or an Untagged VLAN Identifier

When the Access-Accept message returned by RADIUS contains the VLAN information in either vlan-id or vlan-name or U:vlan-id or U:vlan-name format:

  • In single untagged mode (the default), the port membership is removed from the auth-default VLAN and added to the RADIUS-specified VLAN as a MAC-VLAN member.

    The following behavior is the default behavior of the device:

    • Subsequent clients that are authenticated with different dynamic VLANs are blocked.
    • If another client is authenticated on the same VLAN, it is permitted in the first client's dynamic VLAN.
    • If another client is authenticated on the port without a RADIUS VLAN, it is permitted in the first client's dynamic VLAN.
    • Once all the clients in the new VLAN age out, the port is moved back to the auth-default VLAN.

  • In multiple untagged mode, the port is added as a MAC VLAN member to the RADIUS-specified VLAN without removing its membership from the auth-default VLAN.

RADIUS Returns a Single or Multiple Tagged VLAN Identifiers

When the Access-Accept message returned by RADIUS contains the VLAN information in either T:vlan-id or T:vlan-id1; T:vlan-id2 format, for MAC authentication, if the authentication is triggered by a tagged packet and if the VLAN matches the tagged VLAN or VLAN list returned by RADIUS, the session is authenticated, and the port becomes a tagged member of all the dynamically assigned VLANs.

RADIUS Returns Untagged and Single or Multiple Tagged VLAN Identifiers

When the Access-Accept message returned by RADIUS contains the VLAN information in U:vlan-id1; T:vlan-id2 or U:vlan-id1; T:vlan-id2; T:vlan-id3; T:vlan-id4 format:

  • In single untagged mode (the default), the port membership is removed from the auth-default VLAN and added to the RADIUS-specified VLAN as a MAC-VLAN member. It is also added to the tagged VLANs as a tagged member.

    The following behavior is the default behavior of the device:

    • Subsequent clients that are authenticated with different dynamic VLANs are blocked.
    • If another client is authenticated on the same VLAN, it is permitted in the first client's dynamic VLAN.
    • If another client is authenticated on the port without a RADIUS VLAN, it is permitted in the first client's dynamic VLAN.
    • Once all the clients in the new VLAN age out, the port is moved back to the auth-default VLAN.

  • In multiple untagged mode, the port is added as a MAC-VLAN member to the RADIUS-specified untagged VLAN without removing its membership from the auth-default VLAN. It is also added to the tagged VLANs as a tagged member.

For MAC authentication, if the authentication is triggered by a tagged packet and if the VLAN matches the tagged VLAN or VLAN list returned by RADIUS, the session is authenticated, and the port becomes an untagged member of one VLAN and a tagged member of the other dynamically assigned VLANs.

Note: In single untagged mode (the default), if an authenticated client exists on a port and the second client trying to authenticate fails, the port is not moved to a restricted VLAN; instead, the second client is blocked.