
Configuring Access Guardian Policies Configuring 802.1X
page 23-18 OmniSwitch 6800/6850/9000 Network Configuration Guide June 2006
802.1x 2/1 non-supplicant policy authentication
fail vlan 100 default-vlan
If MAC authentication does not return a VLAN
ID, the device is blocked from accessing the switch
on port 2/1.
If the device fails MAC authentication, then the
following occurs:
1 If VLAN 100 exists and is not an authenti-
cated VLAN, the device is assigned to
VLAN 100.
2 If VLAN 100 does not exist or is an authenti-
cated VLAN, the device is assigned to the
default VLAN for port 2/1.
3 If the default VLAN for port 2/1 is an authenti-
cated VLAN, then the device is blocked from
accessing the switch on port 2/1.
802.1x 2/10 non-supplicant policy authentication
pass vlan 10 block fail group-mobility default-vlan
If the MAC authentication process is successful
but does not return a VLAN ID for the device, then
the following occurs:
1 The device is assigned to VLAN 10.
2 If VLAN 10 does not exist, then the device is
blocked from accessing the switch on port
2/10.
If the device fails MAC authentication, then the
following occurs:
1 Group Mobility rules are applied.
2 If Group Mobility classification fails, then the
device is assigned to the default VLAN for
port 2/10.
3 If the default VLAN for port 2/10 is an authen-
ticated VLAN, then the device is blocked from
accessing the switch on port 2/10.
802.1x 3/1 non-supplicant policy authentication
pass vlan 10 block fail group-mobility vlan 43
default-vlan
If the MAC authentication process is successful
but does not return a VLAN ID for the device, then
the following occurs:
1 The device is assigned to VLAN 10.
2 If VLAN 10 does not exist, then the device is
blocked from accessing the switch on port 3/1.
If the device fails MAC authentication, then the
following occurs:
1 Group Mobility rules are applied.
2 If Group Mobility classification fails, then the
device is assigned to VLAN 43.
3 If VLAN 43 does not exist or is an authenti-
cated VLAN, then the device is assigned to the
default VLAN for port 3/1.
4 If the default VLAN for port 3/1 is an authenti-
cated VLAN, then the device is blocked from
accessing the switch on port 3/1.
Supplicant Policy Command Example Description
Komentarze do niniejszej Instrukcji