测试以下auth fail vlan critical vlan但不成功, 是配置问题吗?
vlan 和DHCP等配置已测过没问题, 测正常用户登录也成功, 但特测登录失败操作和断开iMC(测逃生critical vlan)不成功....用户拿不到IP
dot1x
dot1x authentication-method eap
dot1x retry 10
dot1x timer handshake-period 20
dot1x timer reauth-period 7200
dot1x timer tx-period 10
interface GigabitEthernet1/0/5
port link-type hybrid
undo port hybrid vlan 1
port hybrid vlan 5 to 8 untagged
port hybrid pvid vlan 7
stp edged-port
dot1x
undo dot1x handshake
dot1x mandatory-domain radius_domain
undo dot1x multicast-trigger
dot1x re-authenticate
dot1x unicast-trigger
dot1x auth-fail vlan 7
dot1x critical vlan 8
dot1x critical eapol
[sw2]*Jan 7 22:08:46:359 2013 sw2 DOT1X/7/EVENT: BE is in Idle state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:359 2013 sw2 DOT1X/7/EVENT: PAE is in Aborting state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:359 2013 sw2 DOT1X/7/EVENT: BE is in Initialize state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:360 2013 sw2 DOT1X/7/EVENT: PAE is in Disconnect state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:360 2013 sw2 DOT1X/7/EVENT: BE is in Idle state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:360 2013 sw2 DOT1X/7/EVENT: Interface GigabitEthernet1/0/5 received Set the port authorization status to unauthorized event.
*Jan 7 22:08:46:679 2013 sw2 DOT1X/7/EVENT: Processing new mac event: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:684 2013 sw2 DOT1X/7/EVENT: PAE is in Disconnect state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:684 2013 sw2 DOT1X/7/EVENT: BE is in Initialize state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:684 2013 sw2 DOT1X/7/EVENT: PAE is in Restart state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:685 2013 sw2 DOT1X/7/EVENT: BE is in Idle state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:685 2013 sw2 DOT1X/7/EVENT: PAE is in Connecting state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:685 2013 sw2 DOT1X/7/EVENT: PAE is in Authenticating state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:685 2013 sw2 DOT1X/7/EVENT: BE is in Request state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:46:686 2013 sw2 DOT1X/7/EVENT: Sending EAP packet: Identifier=1, type=1.
*Jan 7 22:08:46:686 2013 sw2 DOT1X/7/PACKET:
Transmitted a packet on interface GigabitEthernet1/0/5.
Destination Mac Address=c85b-76f6-fa72
Source Mac Address=9ce8-953c-d194
VLAN ID=7
[sw2]d*Jan 7 22:08:57:359 2013 sw2 DOT1X/7/EVENT: BE is in Request state: UserMAC=c85b-76f6-fa72, VLANID=7, Interface=GigabitEthernet1/0/5.
*Jan 7 22:08:57:359 2013 sw2 DOT1X/7/EVENT: Sending EAP packet: Identifier=1, type=1.
*Jan 7 22:08:57:360 2013 sw2 DOT1X/7/PACKET:
Transmitted a packet on interface GigabitEthernet1/0/5.
Destination Mac Address=c85b-76f6-fa72
Source Mac Address=9ce8-953c-d194
VLAN ID=7
Mac Frame Type=888e
Protocol Version ID=1
Packet Type=0
Packet Length=5
-----Packet Body-----
Code=1
Identifier=1
Length=1280
(0)
最佳答案
看看是否涉及如下限制?
802.1X Critical VLAN功能允许用户在认证时,当所有认证服务器都不可达的情况下访问某一特定VLAN中的资源,这个VLAN称之为Critical VLAN。目前,只采用RADIUS认证方式的情况下,在所有RADIUS认证服务器都不可达后,端口才会加入Critical VLAN。若采用了其它认证方式,则端口不会加入Critical VLAN
另外接口上需要开启mac-vlan enable
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
不应该呀,还有这个说法:在接入控制方式为MAC-based的端口上,当处于Auth-Fail VLAN的用户再次发起认证时,如果认证服务器不可达,则该用户仍然留在该Auth-Fail VLAN中,不会离开当前的VLAN而加入802.1X Critical VLAN。 再不行,联系400帮忙debug分析吧