Ruijie Community
Title: How to Implement Free Authentication for a Single VLAN in DOT1X/Web Environment? [Print this page]
Author: admin Time: 2017-5-3 16:25
Title: How to Implement Free Authentication for a Single VLAN in DOT1X/Web Environment?
How to Implement Free Authentication for a Single VLAN in DOT1X/Web Environment?
Author: admin Time: 2017-5-3 16:25
A free-authenticated VLAN can be configured so that users in the specified VLAN can access the Internet without passing the DOT1X authentication or Web authentication. A device on which free-authenticated VLANs are configured directly skips the access control detection when receiving packets from VLANs contained in the free-authenticated VLAN list, thereby allowing users in free-authenticated VLANs to access the Internet without authentication. The free-authenticated VLAN function can be considered as one application of the secure channel. No free-authenticated VLAN is configured by default. The configuration command is as follows:
[Command] Global mode:[no] direct-vlan vlanlist //no: Indicates that free–authenticated VLANs are deleted if this option is configured. vlanlist: Indicates the configured or deleted free-authenticated VLAN list.
Example: Configure VLAN 100 and VLAN 200 as free-authenticated VLANs and display configured free-authenticated VLANs.
Ruijie(config)#direct-vlan 100,200 //Configure VLAN 100 and VLAN 200 as free-authenticated VLANs.
Ruijie#show direct-vlan//Check free-authenticated VLANs configured on the device.
direct-vlan 100,200
Notes:
1. The N18000, 86E, and 78E support a maximum of 100 free-authenticated VLANs currently.
2. Free-authenticated VLANs occupy hardware entries. If authentication and other access control functions are disabled, the effects are the same regardless of whether free-authenticated VLANs are configured. It is recommended that free-authenticated VLANs be configured for special users who request to access the Internet without authentication only when relevant access control functions are enabled.
3. Free-authenticated VLANs do not participate in the access authentication detection but must pass the security ACL check. If specified users or VLANs that are not allowed to pass are configured in the ACL, the users cannot access the Internet even though free-authenticated VLANs are configured for them. Therefore, when configuring the ACL, do not add a specified VLAN or users in a specified VLAN to the ACL so that users in the free-authenticated VLAN can truly access the Internet without authentication.
Welcome to Ruijie Community (https://community.ruijienetworks.com/) |
Powered by Discuz! X3.2 |