Users Guide

Table Of Contents
430 Authentication, Authorization, and Accounting
The enrollment server supplies 802.1X credentials to the client as part of
enrollment and the client authenticates immediately into the secure or
guest VLAN using those credentials. Alternatively, the client may
temporarily reset the interface prior to authenticating. This places the port
back into the pre-enrollment state.
The enrollment server enrolls the client MAC address and returns a
RADIUS Access-Accept with the guest or secure VLAN in response to the
MAB Access-Request. Alternatively, the client may temporarily reset the
interface prior to authenticating. This places the port back into the pre-
enrollment state.
The enrollment server sends a COA request to the NAS, placing the client
into the secure or guest VLAN, and may apply a DACL or named ACL to
further enable or restrict access. The request may be a simple COA request
with a VLAN or a bounce port request with a new VLAN. (Supported post
version 6.7)
Clients failing the enrollment process may also be placed into an
unauthenticated or guest VLAN via configuration on the switch (802.1x/MAB
timeout) or left in the walled garden.