Configuration Guide Vol. 2


5.3.7 Operation when dot1q is set to MAC

If you use the switchport mac dot1q vlan configuration command to configure dot1q at a MAC port, tagged frames entering that port are authenticated according to fixed VLAN mode.

Untagged frames are authenticated according to dynamic VLAN mode. Note that untagged frames are associated with the native VLAN prior to authentication and with the designated VLAN ID after successful authentication.

The following figure describes the operation of the MAC port with dot1q configured:

Figure 5-8: Behavior when dot1q is set for MAC

[Figure Data]

If the mac-authentication dot1q-vlan force-authorized configuration command is applied to the MAC port, the switch will forward tagged frames from that port without requiring it to undergo MAC-based authentication.

Because a terminal thus exempted from authentication is treated as an authenticated MAC terminal, keep the following in mind:

The following table describes the operation of Layer 2 authentication with dot1q configured at a MAC port:

Table 5-22: Layer 2 Authentication Operation When dot1q is Configured for MAC Ports

Frame type

IEEE802.1X

Web Authentication

MAC-based Authentication

Untagged frame

Subject to VLAN-based authentication (dynamic)

Subject to authentication in dynamic VLAN mode

Subject to authentication in dynamic VLAN mode

Tagged frame

Subject to VLAN-based authentication (static)

Cannot be authenticated

Subject to authentication in fixed VLAN mode