<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 802.1X Dynamic VLAN Compatibility in Security e-Series</title>
    <link>https://community.hpe.com/t5/security-e-series/802-1x-dynamic-vlan-compatibility/m-p/6939470#M881</link>
    <description>&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;I'd like a simple answer from HP: Which Switch series has the capability to set dynamic vlan assignment in 802.1X?&lt;/P&gt;&lt;P&gt;Procurve series only? ( I'm inclined to believe "any" procurve is able to do this )&lt;/P&gt;&lt;P&gt;I've been trying to get it working with OfficeConnect series ( HP1910/1920 series&amp;nbsp; and 3COM 2829 series ).&lt;/P&gt;&lt;P&gt;I get the authentication to work, the Guest and Auth-Fail VLANs working correctly.&lt;/P&gt;&lt;P&gt;I'm using FreeRADIUS server ( simple setup, testing purpose at the moment ), here's my user for trying to assign VLAN100 once authenticated:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;vlan100 Cleartext-Password := "@vlan100"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3Com-VLAN-Name = VLANTEST100,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HP-Egress-VLAN-Name = VLANTEST100,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HP-Egress-VLANID = 100,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel-Type = VLAN,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel-Medium-Type = IEEE-802,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel-Private-Group-Id = 100,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Egress-VLAN-Name = VLANTEST100,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Egress-VLANID = 100,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3Com-User-Access-Level = 3Com-Administrator&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking for second hand, cheap Switches capable of this feature, for my home office lab and I found these modesl ( cheapest first ):&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;HP Procurve A3100 - Jd317a&lt;/LI&gt;&lt;LI&gt;Hp Procurve Switch 2650 - J4899c&lt;/LI&gt;&lt;LI&gt;HP Procurve 1410 - J9561a&lt;/LI&gt;&lt;LI&gt;Hp Procurve E2510g - J9279a&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'm inclined to buy J9279a... I thinks it's the best money for the bucket. I just want the one with the most features of all series above, including the VLAN assignment function.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Sun, 12 Feb 2017 15:51:17 GMT</pubDate>
    <dc:creator>msilveirabr</dc:creator>
    <dc:date>2017-02-12T15:51:17Z</dc:date>
    <item>
      <title>802.1X Dynamic VLAN Compatibility</title>
      <link>https://community.hpe.com/t5/security-e-series/802-1x-dynamic-vlan-compatibility/m-p/6939470#M881</link>
      <description>&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;I'd like a simple answer from HP: Which Switch series has the capability to set dynamic vlan assignment in 802.1X?&lt;/P&gt;&lt;P&gt;Procurve series only? ( I'm inclined to believe "any" procurve is able to do this )&lt;/P&gt;&lt;P&gt;I've been trying to get it working with OfficeConnect series ( HP1910/1920 series&amp;nbsp; and 3COM 2829 series ).&lt;/P&gt;&lt;P&gt;I get the authentication to work, the Guest and Auth-Fail VLANs working correctly.&lt;/P&gt;&lt;P&gt;I'm using FreeRADIUS server ( simple setup, testing purpose at the moment ), here's my user for trying to assign VLAN100 once authenticated:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;vlan100 Cleartext-Password := "@vlan100"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3Com-VLAN-Name = VLANTEST100,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HP-Egress-VLAN-Name = VLANTEST100,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HP-Egress-VLANID = 100,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel-Type = VLAN,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel-Medium-Type = IEEE-802,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel-Private-Group-Id = 100,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Egress-VLAN-Name = VLANTEST100,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Egress-VLANID = 100,&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3Com-User-Access-Level = 3Com-Administrator&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking for second hand, cheap Switches capable of this feature, for my home office lab and I found these modesl ( cheapest first ):&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;HP Procurve A3100 - Jd317a&lt;/LI&gt;&lt;LI&gt;Hp Procurve Switch 2650 - J4899c&lt;/LI&gt;&lt;LI&gt;HP Procurve 1410 - J9561a&lt;/LI&gt;&lt;LI&gt;Hp Procurve E2510g - J9279a&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'm inclined to buy J9279a... I thinks it's the best money for the bucket. I just want the one with the most features of all series above, including the VLAN assignment function.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Sun, 12 Feb 2017 15:51:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/security-e-series/802-1x-dynamic-vlan-compatibility/m-p/6939470#M881</guid>
      <dc:creator>msilveirabr</dc:creator>
      <dc:date>2017-02-12T15:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X Dynamic VLAN Compatibility</title>
      <link>https://community.hpe.com/t5/security-e-series/802-1x-dynamic-vlan-compatibility/m-p/6939803#M895</link>
      <description>&lt;P&gt;Well....&lt;/P&gt;&lt;P&gt;It turns out it was needed to fine tune freeradius....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example of working user:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;vlan15 Cleartext-Password := "@vlan15"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;Tunnel-Type = VLAN,&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;Tunnel-Medium-Type = IEEE-802,&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;Tunnel-Private-Group-Id = 15&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in /etc/raddb/eap.conf:&lt;/P&gt;&lt;P&gt;Into eap/peap, changed&amp;nbsp;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;use_tunneled_reply = no&lt;/STRONG&gt;&lt;/FONT&gt; &amp;nbsp;to&amp;nbsp;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;use_tunneled_reply = yes&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In /etc/raddb/default and /etc/raddb/inner-tunnel ( not sure if this is really required ):&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;# eap {&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;# ok = return&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;# }&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;eap&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And it is working with V1910 both 3com brand SFP Plus and HP brand&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've managed to get Windows to authenticate/work correctly as well as my OpenWRT setup.&lt;/P&gt;&lt;P&gt;My linux box ( Fedora24 ) isn't very happy yet, I still have to debug the issues with TLS.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2017 02:34:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/security-e-series/802-1x-dynamic-vlan-compatibility/m-p/6939803#M895</guid>
      <dc:creator>msilveirabr</dc:creator>
      <dc:date>2017-02-14T02:34:29Z</dc:date>
    </item>
  </channel>
</rss>

