Wired Intelligent Edge

last person joined: yesterday 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

Change port configuration - Multiple fallback vlans

This thread has been viewed 1 times
  • 1.  Change port configuration - Multiple fallback vlans

    Posted Nov 15, 2018 09:04 AM
      |   view attached

    Hello everyone !

     

    A customer have a particular demand. I'm going to try to explain it :

     

    He has stacks of switches (from 4 to 9 members).

    Some ports are "PROD" ports and the others are "GUEST" ports.

    All these ports à configured for 802.1X authentication. If the authentication is succesful, then ClearPass push the correct vlan, that's fine.


    However, when the authentication fails, then there is a fallback vlan which depends on the type of port :

     

    - If the port is a "GUEST", then the fallback vlan is "VLAN GUEST".

     

    - If the port is a "PROD", then the fallback vlan will depends on the port number in the stack

    -if 1<port number<48 then the fallback vlan is VLAN_100
    -if 49<port number<96 then the fallback vlan is VLAN_200
    -if 97<port number<144 then the fallback vlan is VLAN_300
    -ETC.


    He asked me if there is a fast and easy way to change the type of port, without reconfiguring the port manually.

     

    For example the port number 38 is a "GUEST" port, and he wants to changes it into a "PROD" port, without reconfiguring the fallback VLANs.

     

    According to me, some programmation is needed. What would be needed to make that possible ?

    Thanks in advance for your help and for reading ! :)

     

    PS : I put a schema, to make it the most understandable !



  • 2.  RE: Change port configuration - Multiple fallback vlans

    MVP GURU
    Posted Nov 21, 2018 07:19 AM

    i think, it will be possible with ClearPass (on Enforcement...) but i will no be easy...

     

    Switch need really to be stacked ?