- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Re: dynamic vlans
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-22-2006 01:18 AM
тАО09-22-2006 01:18 AM
dynamic vlans
Is it possible (HP2600 or HP5400) to dynamicaly affect vlan regarding the host's IP address ?
This is my problem : I have 1 network 192.168.1.xx/24 for most of users (DEFAULT_VLAN), 1 network 192.168.2.yy/24 for group 1 of automates (VLAN_2) and 1 network 192.168.3.zz/24 for group 2 of automates (VLAN_3). Is it possible NOT to statically affect ports of the switch i.e. I plug a machine anywhere and it goes on its own vlan according to its IP address ?
Next, I will have several switches...
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-22-2006 03:53 AM
тАО09-22-2006 03:53 AM
Re: dynamic vlans
Yes its possible, by usuing one the the 802.1X advantages, which is Dynamic Vlans assignment.
What you need is an 802.1x aware switches (both 5400 and 2600 support it), and a RADIUS server.
Configuration is easy, once the user connect to any port on the switch, he has to authenticate, and once authentication done, the RADIUS server will pass this user's Vlan assignment with his privileges and attributes.
Read more about this in the following link, ch11 :
ftp://ftp.hp.com/pub/networking/software/3500_5400_6200_AccSecGde-July2006-59913828.pdf
Good Luck !!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-24-2006 06:21 PM
тАО09-24-2006 06:21 PM
Re: dynamic vlans
If i have understood what you say, the user has to authenticate...
But what I need is to assign vlan regarding host's IP, nothing else... Is it possible on 5400 ?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-24-2006 06:34 PM
тАО09-24-2006 06:34 PM
Re: dynamic vlans
Let me ask you ? how can the switch knows who plugged in, so it can give him and IP address and a Vlan also.
You need something to recognize the person.
You can do MAC address authentication, but its a headache.
Lets say i connect my pc to a port of the 5400, the switch will direct my DHCP request to a proper DHCP server, and i get an IP, then what ????
Usually in Multiple Vlan situation, we try to get the Vlan of the user and send it along with the DHCP request to the DHCP server, where we have multiple scopes for each Vlan, then give the user a proper IP withing his vlan subnet.
With 802.1x, we authenticate the user, the get his Vlan along with an proper IP, but all done by an external authentication server and active directory.
Good Luck !!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-25-2006 06:27 PM
тАО09-25-2006 06:27 PM
Re: dynamic vlans
I have one network for standard PCs, another one for industrial machines, and so on...
In fact, DHCP will be used only for standard PCs (if possible)...
Is it possible without using 802.11x ? (industrial machines like 'Allen Bradley' automates don't authenticate on the network !!!)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-25-2006 06:44 PM
тАО09-25-2006 06:44 PM
Re: dynamic vlans
When the client connects to a port, the switch will authenticate the client mac-address with the RADIUS server, which in turn will return the switch with the correct VLAN ID for that particular mac-address.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-05-2006 12:15 AM
тАО10-05-2006 12:15 AM