EasyManuals Logo

Cisco 300 Series Administration Guide

Cisco 300 Series
586 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #428 background imageLoading...
Page #428 background image
Security: 802.1X Authentication
Authenticator Overview
Cisco Small Business 200, 300 and 500 Series Managed Switch Administration Guide (Internal Version) 391
19
Host Modes with Guest VLAN
The host modes work with guest VLAN in the following way:
• Single-Host and Multi-Host Mode
Untagged traffic and tagged traffic belonging to the guest VLAN arriving on
an unauthorized port are bridged via the guest VLAN. All other traffic is
discarded. The traffic belonging to an unauthenticated VLAN is bridged via
the VLAN.
• Multi-Sessions Mode in Layer 2
Untagged traffic and tagged traffic, which does not belong to the
unauthenticated VLANs and that arrives from unauthorized clients, are
assigned to the guest VLAN using the TCAM rule and are bridged via the
guest VLAN. The tagged traffic belonging to an unauthenticated VLAN is
bridged via the VLAN.
This mode cannot be configured on the same interface with policy-based
VLANs.
• Multi-Sessions Mode in Layer 3
The mode does not support the guest VLAN.
RADIUS VLAN Assignment or Dynamic VLAN Assignment
An authorized client can be assigned a VLAN by the RADIUS server, if this option
is enabled in the Port Authentication page. This is called either Dynamic VLAN
Assignment (DVA) or RADIUS-Assigned VLAN. In this guide, the term RADIUS-
Assigned VLAN is used.
When a port is in multi-session mode and RADIUS-Assigned VLAN is enabled, the
device automatically adds the port as an untagged member of the VLAN that is
assigned by the RADIUS server during the authentication process. The device
classifies untagged packets to the assigned VLAN if the packets originated from
the devices or ports that are authenticated and authorized.
See Table 3 Guest VLAN Support and RADIUS-VLAN Assignment Support and
The following table describes how authenticated and non-authenticated
traffic is handled in various situations. for further information about how the
different modes behave when RADIUS-Assigned VLAN is enabled on the device.
NOTE . In multi-session mode, RADIUS VLAN assignment is only supported when the
device is in Layer 2 system mode.

Table of Contents

Other manuals for Cisco 300 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 300 Series and is the answer not in the manual?

Cisco 300 Series Specifications

General IconGeneral
ModelCisco 300 Series
CategorySwitch
DimensionsVaries by model
WeightVaries by model
Power over Ethernet (PoE)Available on select models
ManagementWeb-based GUI, SNMP, CLI
VLANsUp to 256
Security FeaturesACLs, 802.1X, Port Security
Humidity10% to 90% non-condensing
Ports8, 16, 24, 48

Related product manuals