iii
802.1X guest VLAN and authorization VLAN configuration example ···················································· 104
802.1X with ACL assignment configuration example ············································································· 107
802.1X with EAD assistant configuration example (with DHCP relay agent) ········································· 108
802.1X with EAD assistant configuration example (with DHCP server) ················································· 111
Troubleshooting 802.1X ································································································································· 113
EAD assistant URL redirection failure ···································································································· 113
Configuring MAC authentication ································································· 115
Overview ························································································································································ 115
User account policies ····························································································································· 115
Authentication methods ·························································································································· 115
VLAN assignment ·································································································································· 116
ACL assignment ····································································································································· 118
User profile assignment ························································································································· 118
Redirect URL assignment ······················································································································ 119
Configuration prerequisites ···························································································································· 119
Configuration task list ····································································································································· 119
Enabling MAC authentication ························································································································· 119
Specifying a MAC authentication domain ······································································································ 120
Configuring the user account format ·············································································································· 120
Configuring MAC authentication timers ········································································································· 121
Setting the maximum number of concurrent MAC authentication users on a port ········································· 121
Enabling MAC authentication multi-VLAN mode on a port ············································································ 122
Configuring MAC authentication delay ··········································································································· 122
Enabling parallel processing of MAC authentication and 802.1X authentication ··········································· 123
Configuration restrictions and guidelines ······························································································· 123
Configuration procedure ························································································································· 123
Configuring a MAC authentication guest VLAN ····························································································· 124
Configuring a MAC authentication critical VLAN ···························································································· 125
Enabling the MAC authentication critical voice VLAN ···················································································· 125
Configuration prerequisites ···················································································································· 125
Configuration procedure ························································································································· 126
Configuring periodic MAC reauthentication ··································································································· 126
Overview ················································································································································ 126
Configuration restrictions and guidelines ······························································································· 126
Configuration procedure ························································································································· 127
Enabling MAC authentication offline detection ······························································································ 127
Displaying and maintaining MAC authentication ···························································································· 128
MAC authentication configuration examples ·································································································· 128
Local MAC authentication configuration example ·················································································· 128
RADIUS-based MAC authentication configuration example ·································································· 130
ACL assignment configuration example································································································· 132
Configuring portal authentication ································································ 136
Overview ························································································································································ 136
Extended portal functions ······················································································································· 136
Portal system components ····················································································································· 136
Portal system using the local portal Web server ···················································································· 138
Interaction between portal system components ····················································································· 138
Portal authentication modes ··················································································································· 139
Portal support for EAP ··························································································································· 139
Portal authentication process ················································································································· 140
Portal packet filtering rules ····················································································································· 142
MAC-based quick portal authentication ································································································· 142
Portal configuration task list ··························································································································· 143
Configuration prerequisites ···························································································································· 144
Configuring a portal authentication server ····································································································· 144
Configuring a portal Web server ···················································································································· 145
Enabling portal authentication ························································································································ 146
Configuration restrictions and guidelines ······························································································· 146
Configuration procedure ························································································································· 147
Specifying a portal Web server ······················································································································ 147