Configuration Considerations and Guidelines for Flexible Authentication
- In FastIron release 08.0.90 and later releases, there will no longer be any link flap when a port is being added as a tagged member to a VLAN for the first time or when a port is being removed from the last tagged VLAN. External devices that may have relied on this link flap in the past for any kind of renegotiation must be reconfigured appropriately, or you must manually flap the interface.
- The RADIUS server must be configured to support a specific authentication method or a combination of authentication methods. A RADIUS server can be configured to use only 802.1X authentication, MAC authentication, or Web authentication or a combination of these authentication methods. For more information about RADIUS configuration, refer to RADIUS Authentication.
- MACsec and Flexible authentication cannot be configured on the same port.
- Flexible authentication and MVRP cannot be enabled on the same port.
- MVRP dynamic VLANs cannot be configured as authentication VLANs (auth-default VLAN, guest VLAN, critical VLAN, or restricted VLAN). This limitation applies at both the global configuration and interface configuration levels.
- Flexible authentication cannot be enabled on ports that have any of the following features enabled:
- Incoming traffic on unauthenticated ports is blocked by ICX devices, while allowing for outgoing broadcasts and multicasts to account for waking connected devices that are in a sleep state. This is the default behavior, and there is no configuration option.
- If Web authentication is enabled on the restricted VLAN, critical VLAN, guest VLAN, or a RADIUS-assigned VLAN, the device uses Web authentication as a fallback or additional authentication method. Web authentication can be enabled on eight VLANs.
When
authentication allow-tagged enablecommand is enabled, the IEEE 802.1x client must ensure that it sends tagged traffic which is returned by RADIUS VLAN. If the client sends traffic with a VLAN that is not allowed or blocked, the traffic will be forwarded to the CPU, resulting in high CPU usage.- The client session establishes a relationship between the username and MAC address used for authentication. If attempting to gain access from different clients (with different MAC addresses), the user must be authenticated from each client.
- When a client is denied access to the network, its session is aged out if no traffic is received from the client MAC address over a default hardware aging period (70 seconds), plus a software aging period. Both these age intervals can be changed, or session aging can be disabled altogether. After the denied client session is aged out, traffic from that client is no longer blocked, and the client can be reauthenticated.
- In the
authentication filtercommand used to configure authentication override for specified MAC addresses, the statements "permit any any" and "deny any any" are not allowed.