XGS-5240-Series User Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
47-13
network, while the others can not. When one user becomes offline, the other
users will not be affected.
When the user-based (IP address+ MAC address+ port) method is used, all u
sers can access limited resources before being authenticated. There are two ki
nds of control in this method: standard control and advanced control. The user
-based standard control will not restrict the access to limited resources, which
means all users of this port can access limited resources before being authent
icated. The user-based advanced control will restrict the access to limited reso
urces, only some particular users of the port can access limited resources bef
ore being authenticated. Once those users pass the authentication, they can a
ccess all resources.
Attention: when using private supplicant systems, user-based advanced control is re
commended to effectively prevent ARP cheat.
The maximum number of the authenticated users can be 4000, but less than 2000
will be preferred.
47.1.7 The Features of VLAN Allocation
1. Auto VLAN
Auto VLAN feature enables RADIUS server to change the VLAN to which the acce
ss port belongs, based on the user information and the user access device information.
When an 802.1x user passes authentication on the server, the RADIUS server will sen
d the authorization information to the device, if the RADIUS server has enabled the VL
AN-assigning function, then the following attributes should be included in the Access-Ac
cept messages:
Tunnel-Type = VLAN (13)
Tunnel-Medium-Type = 802 (6)
Tunnel-Private-Group-ID = VLANID
The VLANID here means the VID of VLAN, ranging from 1 to 4094. For example,
Tunnel-Private-Group-ID = 30 means VLAN 30.
When the switch receives the assigned Auto VLAN information, the current Access
port will leave the VLAN set by the user and join Auto VLAN.
Auto VLAN won’t change or affect the port’s configuration. But the priority of Auto
VLAN is higher than that of the user-set VLAN, that is Auto VLAN is the one takes eff
ect when the authentication is finished, while the user-set VLAN do not work until the
user become offline.
Notes: At present, Auto VLAN can only be used in the port-based access control