Creating Authentication Profiles

Creating and managing authentication profiles defines how 802.1X and MAC-authentication actions are processed in the switch. This includes specifying actions for authentication failures and authentication timeout, and assigning VLANs for critical, guest, and restricted access scenarios.

Configure at least one authentication profile in the group for port-based authentication. Complete the following steps to create a authentication profile for the selected Switch Group.

  1. In the main menu, navigate to Network > Wired > Switches.
    The Switches page is displayed.
  2. In the Switches page, select the Switch Group that you want to configure, and scroll to the Details section.
  3. In the Details section, click the Configuration tab.
  4. In the Configuration tab, click Authentication Profiles.
  5. In the Authentication Profiles page, click Create to create a new profile or select an existing profile and click Next to edit it.
  6. Configure the following parameters.
    1. Profile Name: Provide a name for this profile.
    2. Type: Select one of the following options.
      • 802.1x: Only 802.1X authentication will be processed.
      • MAC-AUTH: Only MAC authentication will be processed.
      • 802.1x and MAC-AUTH: Either 802.1X or MAC authentication will be processed in the selected order.
    3. Change Authentication Order: This option is available when the Type is selected as 802.1x and MAC-AUTH. By default, 802.1X authentication is processed first and the MAC authentication is only processed if the authentication server is not responding. Enable the toggle to change the authentication order and process MAC authentication first.
    4. 802.1X Port Control: This option is available when the Type is selected as 802.1x.

      Select one of the following options:

      • Auto: The authorization state of the port depends on the response from the server. If the authentication server responds with an access-accept, then the port will be authorized, otherwise, it will remain unauthorized.
      • Force Authorized: The ports will be in the authorized state skipping the authentication process.
      • Force Unauthorized: The ports will be in an unauthorized state skipping the authentication process.
    5. Auth Default VLAN: All ports belong to this VLAN before any authentication process is started.
    6. Fail Action: Indicates what action to take if the authentication is denied.

      Choose one of the following options:

      • Restricted VLAN: The port is placed in the restricted VLAN. When you select this option, you must also specify the Restricted VLAN number.
      • Block: Place the port in an unauthorized state and any traffic is blocked.
    7. Timeout Action: Indicates what action to take if the authentication does not respond to the authentication request.

      Choose one of the following options:

      • Critical VLAN: The port is placed in the critical VLAN. When you select this option, you must also specify the Restricted VLAN number.
      • Success: Place the port in an authorized state and permit traffic.
      • Failure: Place the port in an unauthorized state and any traffic is blocked.
      • None: The authentication process keeps going indefinitely.

      Note: To learn with detail the definition and function of all the terms and concepts for the authentication profiles, refer to FastIron Security Configuration Guide.

  7. Click OK.

    The Authentication Profiles page closes and the profile is applied to the switches in the group.

    Note: The controller creates in the switch the provided Auth Default VLAN, Restricted VLAN, and Critical VLAN, if they do not exist already in the switch configuration.