88 Device SecurityMaximum Requests............................... 2Max Users...................................... 3Supplicant Timeout............................. 30Server Timeout (secs).......................... 30Logical Supplicant AuthPAE Backend VLAN Username FilterPort MAC-Address State State Id Id------- -------------- -------- -------- ----- -------- ------112 0000.0000.0000 Initialize Idle802.1X Authentication and VLANsThe PowerConnect 6200 Series switches allow a port to be placed into a particular VLAN based on theresult of type of 802.1X authentication a client uses when it accesses the switch. The RADIUS server orIEEE 802.1X Authenticator can provide information to the switch about which VLAN to assign the host(supplicant).When a host connects to a switch that uses a RADIUS server or 802.1X Authenticator to authenticatethe host, the host authentication can typically have one of three outcomes:• The host is authenticated.• The host attempts to authenticate but fail because it lacks certain security credentials.• The host is a guest and does not try to authenticate at all.You can create three separate VLANs on the switch to handle hosts depending on whether the hostauthenticates, fails the authentication, or is a guest. The RADIUS server informs the switch of theselected VLAN as part of the authentication.Authenticated and Unauthenticated VLANsHosts that authenticate normally use a VLAN that includes access to network resources. Hosts that failthe authentication might be denied access to the network or placed on a "quarantine" VLAN withlimited network access.Much of the configuration to assign hosts to a particular VLAN takes place on the RADIUS server or802.1X authenticator. If you use an external RADIUS server to manage VLANs, you configure the serverto use Tunnel attributes in Access-Accept messages in order to inform the switch about the selectedVLAN. These attributes are defined in RFC 2868, and their use for dynamic VLAN is specified in RFC3580.The VLAN attributes defined in RFC3580 are as follows:• Tunnel-Type=VLAN (13)• Tunnel-Medium-Type=802• Tunnel-Private-Group-ID=VLANID