ProCurve Series 2300 and 2500 Switches Release Notes
26
Enhancements in Release F.05.xx
Configuring Port-Based Access Control (802.1x)
■ If a port on switch “A” is configured as both an 802.1x authenticator and supplicant and is
connected to a port on another switch, “B”, that is not 802.1x-aware, access to switch “B”
will occur without 802.1x security protection, but switch “B” will not be allowed access to
switch “A”. This means that traffic on this link between the two switches will flow from “A”
to “B”, but not the reverse.
■ If a client already has access to a switch port when you configure the port for 802.1x
authenticator operation, the port will block the client from further network access until it
can be authenticated.
■ On a port configured for 802.1x with RADIUS authentication, if the RADIUS server specifies
a VLAN for the supplicant and the port is a trunk member, the port will be blocked. If the
port is later removed from the trunk, the port will try to authenticate the supplicant. If
authentication is successful, the port becomes unblocked. Similarly, if the supplicant is
authenticated and later the port becomes a trunk member, the port will be blocked. If the
port is then removed from the trunk, it tries to re-authenticate the supplicant. If successful,
the port becomes unblocked.
■ To help maintain security, 802.1x and LACP cannot both be enabled on the same port. If you
try to configure 802.1x on a port already configured for LACP (or the reverse) you will see
a message similar to the following:
Error configuring port X: LACP and 802.1x cannot be run together.
Note on 802.1x and LACP
To help maintain security, the switch does not allow 802.1x and LACP to both be enabled at the same
time on the same port. Refer to “802.1x Operating Messages” on page -60.
General Setup Procedure for Port-Based Access Control (802.1x)
Do These Steps Before You Configure 802.1x Operation
1. Configure a local username and password on the switch for both the Operator (login) and
Manager (enable) access levels. (While this may or may not be required for your 802.1x
configuration, HP recommends that you use a local username and password pair at least until
your other security measures are in place.)
2. Determine which ports on the switch you want to operate as authenticators and/or supplicants,
and disable LACP on these ports. (See the “Note on 802.1x and LACP” on page -26.)