Users Guide

Table Of Contents
326 Authentication, Authorization, and Accounting
Guest VLAN
The Guest VLAN feature provides a mechanism to allow users access to a
guest VLAN. For example, the administrator might provide a guest VLAN to
visitors and contractors to permit network access that allows visitors to
connect to external network resources, such as the Internet, with no ability to
access information on the internal LAN.
As an example, on a port configured in auto authentication mode
(authentication port-control auto) and connected to a client that does not
support 802.1X, the client does not respond to the 802.1X requests from the
switch. The port remains in the unauthorized state and the client is not
granted access to the network. If a guest VLAN is configured for that port, the
port is placed in the configured guest VLAN and moved to the authorized
state, allowing access to the client over the guest VLAN.
When the guest VLAN capability is disabled, users authorized by the guest
VLAN are removed from the VLAN and denied network access.
RADIUS Trunk Mode Assignment
Some network administrators may choose to use a default configuration on all
ports in the network and administer bespoke network policies via RADIUS.
Dell EMC switches support configuration of switchport trunk mode on ports
via RADIUS. In an 802.1X Access-Accept message, the Cisco VSA device-
traffic-class=switch indicates that the connected device is capable of
forwarding traffic from multiple stations using tagged and untagged traffic.
When an Access-Accept message is received that contains the VSA device-
traffic-class=switch, the switch operationally sets the port to trunk mode and
utilizes the RADIUS-assigned VLAN to set the operational native VLAN. If
not present, the port PVID is used to set the operational trunk port native
VLAN. Spanning-tree portfast is operationally disabled on the port. Any
trunk mode configuration on the port is respected.
NOTE: MAB and the guest VLAN feature are mutually exclusive on a port. If MAB
is enabled on a port concurrently with guest VLAN, the port will not move to the
authorized state.