<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BUG: ProCurve Switch 2510G-48, DHCP problem with 802.1X authenticated VLAN / public VLAN otherwise in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/bug-procurve-switch-2510g-48-dhcp-problem-with-802-1x/m-p/4792150#M26070</link>
    <description>Hello,&lt;BR /&gt;&lt;BR /&gt;It's a good idea, but I don't find any Y 11.18 version on the ProCurve website (&lt;A href="https://h10145.www1.hp.com/Downloads/SoftwareReleases.aspx?ProductNumber=J9280A" target="_blank"&gt;https://h10145.www1.hp.com/Downloads/SoftwareReleases.aspx?ProductNumber=J9280A&lt;/A&gt;〈=en,en&amp;amp;cc=us,us&amp;amp;prodSeriesId=3356807)&lt;BR /&gt;&lt;BR /&gt;Any advise welcome&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;AndrÃ©&lt;BR /&gt;</description>
    <pubDate>Fri, 27 May 2011 12:26:14 GMT</pubDate>
    <dc:creator>SysCo al</dc:creator>
    <dc:date>2011-05-27T12:26:14Z</dc:date>
    <item>
      <title>BUG: ProCurve Switch 2510G-48, DHCP problem with 802.1X authenticated VLAN / public VLAN otherwise</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/bug-procurve-switch-2510g-48-dhcp-problem-with-802-1x/m-p/4792148#M26068</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;Here is the problem:&lt;BR /&gt;&lt;BR /&gt;Material: ProCurve Switch 2510G-48&lt;BR /&gt;Firmware: 11/17/09 Y.11.16&lt;BR /&gt;&lt;BR /&gt;We want to have 802.1X VLAN authentication, and if no authentication is correct, we want to have a public VLAN.&lt;BR /&gt;&lt;BR /&gt;Here is the configuration:&lt;BR /&gt;&lt;BR /&gt;vlan 1&lt;BR /&gt;   name "DEFAULT_VLAN"&lt;BR /&gt;   no ip address&lt;BR /&gt;   no untagged 1-48&lt;BR /&gt;   exit&lt;BR /&gt;vlan 2&lt;BR /&gt;   name "PUBLIC_VLAN"&lt;BR /&gt;   no ip address&lt;BR /&gt;   exit&lt;BR /&gt;vlan 3&lt;BR /&gt;   name "PRIVATE_VLAN"&lt;BR /&gt;   untagged 1-48&lt;BR /&gt;   ip address 192.168.3.1 255.255.255.0&lt;BR /&gt;   exit&lt;BR /&gt;&lt;BR /&gt;aaa authentication port-access eap-radius&lt;BR /&gt;radius-server host 192.168.3.2 key mysecretkey&lt;BR /&gt;primary-vlan 3&lt;BR /&gt;aaa port-access authenticator 1&lt;BR /&gt;aaa port-access authenticator 1 auth-vid 3&lt;BR /&gt;aaa port-access authenticator 1 unauth-vid 2&lt;BR /&gt;aaa port-access authenticator active&lt;BR /&gt;&lt;BR /&gt;Let's do the test on port 1. Once authentication is done and ok (VLAN 3), the DHCP Discovery broadcasted packet is sent (and received by the DHCP server in the VLAN 3), but the DHCP Offer broadcasted answer packet is never going back to the machine.&lt;BR /&gt;&lt;BR /&gt;If we are not authenticated (VLAN 2), everything is working fine, the second DHCP in the VLAN 2 receive the Discovery, send the Offer, receive the Request and send the Acknoledgement packet.&lt;BR /&gt;&lt;BR /&gt;If we connect the machine to the port 2 (always on VLAN 3), the DHCP protocol is working well with the DHCP server in the VLAN 3.&lt;BR /&gt;&lt;BR /&gt;After sniffing everything in any directions, we discovered that ALL broadcast traffic is never going through an authenticated port, BUT this only if the authenticated port is in the same VLAN as the switch management VLAN ! We didn't find any filter that can be removed or setup.&lt;BR /&gt;&lt;BR /&gt;Any suggestion welcome, we have spend hours and hours in our configuration, but this is for sure a bug, not a configuration problem.&lt;BR /&gt;&lt;BR /&gt;Does anybody have a success to do a 802.1X authentication with working DHCP IP distribution in the VLAN of the managed switch with this firmware 11/17/09 Y.11.16 ?&lt;BR /&gt;&lt;BR /&gt;We have tried downgrading to version 11.12 and it works ! But as a lot of other stuffs have been fixed in 11.16, we would be happy to have a new fixed release for our brand new switch (bought a few weeks ago).&lt;BR /&gt;&lt;BR /&gt;Thanks in advance for your support.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;André&lt;BR /&gt;</description>
      <pubDate>Wed, 25 May 2011 16:41:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/bug-procurve-switch-2510g-48-dhcp-problem-with-802-1x/m-p/4792148#M26068</guid>
      <dc:creator>SysCo al</dc:creator>
      <dc:date>2011-05-25T16:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: BUG: ProCurve Switch 2510G-48, DHCP problem with 802.1X authenticated VLAN / public VLAN otherwise</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/bug-procurve-switch-2510g-48-dhcp-problem-with-802-1x/m-p/4792149#M26069</link>
      <description>upgrade your switch y.11.18</description>
      <pubDate>Fri, 27 May 2011 12:00:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/bug-procurve-switch-2510g-48-dhcp-problem-with-802-1x/m-p/4792149#M26069</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2011-05-27T12:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: BUG: ProCurve Switch 2510G-48, DHCP problem with 802.1X authenticated VLAN / public VLAN otherwise</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/bug-procurve-switch-2510g-48-dhcp-problem-with-802-1x/m-p/4792150#M26070</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;It's a good idea, but I don't find any Y 11.18 version on the ProCurve website (&lt;A href="https://h10145.www1.hp.com/Downloads/SoftwareReleases.aspx?ProductNumber=J9280A" target="_blank"&gt;https://h10145.www1.hp.com/Downloads/SoftwareReleases.aspx?ProductNumber=J9280A&lt;/A&gt;〈=en,en&amp;amp;cc=us,us&amp;amp;prodSeriesId=3356807)&lt;BR /&gt;&lt;BR /&gt;Any advise welcome&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;AndrÃ©&lt;BR /&gt;</description>
      <pubDate>Fri, 27 May 2011 12:26:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/bug-procurve-switch-2510g-48-dhcp-problem-with-802-1x/m-p/4792150#M26070</guid>
      <dc:creator>SysCo al</dc:creator>
      <dc:date>2011-05-27T12:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: BUG: ProCurve Switch 2510G-48, DHCP problem with 802.1X authenticated VLAN / public VLAN otherwise</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/bug-procurve-switch-2510g-48-dhcp-problem-with-802-1x/m-p/4792151#M26071</link>
      <description>Yes, contact Procurve support and request the latest software for your switch.  Also request the associated release notes, which they probably won't provide by default.  You should see many AAA/802.1x related bug fixes.  It appears they are not publicly posting switch software that only contains bug fixes, just new features.&lt;BR /&gt;&lt;BR /&gt;Another thought is, I beleive this line of your config is redundant:&lt;BR /&gt;aaa port-access authenticator 1 auth-vid 3&lt;BR /&gt;&lt;BR /&gt;You have already set port 1 as untagged on VLAN 3.  It should work, but I would try removing it to see if it has any impact.</description>
      <pubDate>Fri, 27 May 2011 14:40:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/bug-procurve-switch-2510g-48-dhcp-problem-with-802-1x/m-p/4792151#M26071</guid>
      <dc:creator>Steve Woodward_2</dc:creator>
      <dc:date>2011-05-27T14:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: BUG: ProCurve Switch 2510G-48, DHCP problem with 802.1X authenticated VLAN / public VLAN otherwise</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/bug-procurve-switch-2510g-48-dhcp-problem-with-802-1x/m-p/4792152#M26072</link>
      <description>Thanks for the advise, ticket opened by ProCurve support.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Andre</description>
      <pubDate>Mon, 30 May 2011 19:49:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/bug-procurve-switch-2510g-48-dhcp-problem-with-802-1x/m-p/4792152#M26072</guid>
      <dc:creator>SysCo al</dc:creator>
      <dc:date>2011-05-30T19:49:04Z</dc:date>
    </item>
  </channel>
</rss>

