Administrator Guide

Table Of Contents
282 Authentication, Authorization, and Accounting
Considers the client to be 802.1X unaware client (if it does not receive an
EAP response packet from that client)
The authenticator sends a request to the authentication server with the MAC
address of the client in a hexadecimal format as the username and the MD5
hash of the MAC address as the password. The authentication server checks
its database for the authorized MAC addresses and returns an Access-Accept
or an Access-Reject response, depending on whether the MAC address is
found in the database. MAB also allows 802.1X-unaware clients to be placed
in a RADIUS-assigned VLAN or to apply a specific Filter ID to the client
traffic.
What is the Role of 802.1X in VLAN Assignment?
Dell Networking N-Series switches allow a port to be placed into a particular
VLAN based on the result of the authentication. The authentication server
can provide information to the switch about which VLAN to assign the
supplicant or the administrator can configure the level of access provided
when authentication fails or is never attempted.
When a host connects to a switch that uses an authentication server to
authenticate, the host authentication will have one of three outcomes:
The host is authenticated.
The host attempts to authenticate but fails because it lacks certain
security credentials.
The host does not try to authenticate at all (802.1X unaware).
Three separate VLANs can be created on the switch to handle a host
depending on whether the host authenticates, fails the authentication, or
does not attempt authentication. The RADIUS server informs the switch of
the selected VLAN as part of the authentication.
Authenticated VLANs
Hosts that authenticate normally use a VLAN that includes access to network
resources. This VLAN may be assigned by the RADIUS server. Hosts that fail
authentication might be denied access to the network or placed into a guest
NOTE: MAB initiates only after the dot1x guest VLAN period times out. If the client
responds to any of the EAPOL identity requests, MAB does not initiate for that
client.