Configuration Guide Vol. 2


8.2.2 Dynamic VLAN

When a terminal with membership to the pre-authentication VLAN undergoes successful authentication in dynamic VLAN mode, the switch registers the terminal in a MAC VLAN and enters it in a MAC address table based on the VLAN ID provided by the internal Web authentication DB or the RADIUS server. As a result, the terminal gains access to the post-authentication VLAN. For this to work, the following configuration is required:

<Structure of this section>

(1) Local authentication method

The figure below describes local authentication using an internal Web authentication DB.

Figure 8-4: Configuration of the local authentication method for dynamic VLAN

[Figure Data]

  1. A user of a PC connected via a hub opens a Web browser and accesses the Switch.

  2. The Switch compares the user ID and password entered by the user against the user information in the internal Web authentication DB.

  3. If authentication succeeds, a page appears on the PC indicating that authentication was successful, and the PC gains membership to the post-authentication VLAN.

  4. The authenticated PC is able to access servers in the post-authentication VLAN.

(2) RADIUS authentication-method

The figure below describes RADIUS authentication using a RADIUS server.

Figure 8-5: Configuration of RADIUS authentication-method for dynamic VLAN

[Figure Data]

  1. A user of a PC connected via a hub opens a Web browser and accesses the Switch.

  2. Authentication takes place by comparing the user ID and password entered by the user against the user information registered on the RADIUS server.

  3. If authentication succeeds, a page appears on the PC indicating that authentication was successful, and the PC gains membership to the post-authentication VLAN.

  4. The authenticated PC is able to access servers in the post-authentication VLAN.