<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configure 802.1x auth on 7150 stacks in ICX Switches</title>
    <link>https://community.ruckuswireless.com/t5/ICX-Switches/Configure-802-1x-auth-on-7150-stacks/m-p/30807#M1707</link>
    <description>&lt;P style="margin: 0;"&gt;I need to get 802.1x auth configured on all of our ICX 7150 switches, and am reading through the documentation trying to learn. I came across this in the Security Guide/Flexible Authentication section:&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;"Before authentication is enabled on a port, the port can belong to any VLAN, including the system default VLAN. The only restriction is that the port cannot be a part of any VLAN as untagged."&amp;nbsp;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Am I understanding this correctly? No ports can have an untagged VLAN on them at all?&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;As it stands today, all ports on our "IDF" or "Access" switches (switches that provide the end users ports to plug into), are unstagged on VLAN 1 and tagged on VLAN 333.&amp;nbsp; VLAN 1 is what our main IP network is on... client machines, some servers, etc. VLAN 333 is used for our Mitel phone system and IP phone sets. So, if a Mitel IP phone is plugged into a port, it will get some DHCP options passed to it that will get it on the 333 VLAN (tagged) and the computer pass-through port on the back of the phone stays untagged on VLAN 1.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;I am having a hard time understanding how this will work if we can't have VLAN 1 untagged on our ports?&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Here is an example switch config currently;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;ver 08.0.95bT213&lt;BR /&gt;!&lt;BR /&gt;stack unit 1&lt;BR /&gt;&amp;nbsp; module 1 icx7150-24p-poe-port-management-module&lt;BR /&gt;&amp;nbsp; module 2 icx7150-2-copper-port-2g-module&lt;BR /&gt;&amp;nbsp; module 3 icx7150-4-sfp-plus-port-40g-module&lt;BR /&gt;&amp;nbsp; stack-port 1/3/1&lt;BR /&gt;&amp;nbsp; stack-port 1/3/3&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;global-stp&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;vlan 1 name DEFAULT-VLAN by port&lt;BR /&gt;&amp;nbsp;router-interface ve 1&lt;BR /&gt;&amp;nbsp;spanning-tree&lt;BR /&gt;!&lt;BR /&gt;vlan 25 name Honeywell by port&lt;BR /&gt;&amp;nbsp;tagged ethe 1/3/1 to 1/3/4&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;vlan 101 name NAC_Corp1_WLAN_101 by port&lt;BR /&gt;&amp;nbsp;tagged ethe 1/1/1 to 1/1/24 ethe 1/3/1 to 1/3/4&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;vlan 106 name NAC_Warehouse_WLAN_106 by port&lt;BR /&gt;&amp;nbsp;tagged ethe 1/1/1 to 1/1/24 ethe 1/3/1 to 1/3/4&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;vlan 107 name NAC_Employee_Phone_WLAN_07 by port&lt;BR /&gt;&amp;nbsp;tagged ethe 1/1/1 to 1/1/24 ethe 1/3/1 to 1/3/4&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;vlan 108 name "Ruckus AP" by port&lt;BR /&gt;&amp;nbsp;tagged ethe 1/3/3&amp;nbsp;&lt;BR /&gt;&amp;nbsp;untagged ethe 1/1/21&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;vlan 333 name "voip vlan" by port&lt;BR /&gt;&amp;nbsp;tagged ethe 1/1/1 to 1/1/20 ethe 1/1/22 to 1/1/24 ethe 1/3/1 to 1/3/4&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;enable aaa console&lt;BR /&gt;hostname "IDF EXP OFFICE"&lt;BR /&gt;ip dns server-address 8.8.8.8&lt;BR /&gt;ip route 0.0.0.0/0 190.1.200.235&lt;BR /&gt;!&lt;BR /&gt;telnet timeout 10&lt;BR /&gt;no telnet server&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ntp&lt;BR /&gt;&amp;nbsp;server ntp.ruckuswireless.com&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;manager registrar&lt;BR /&gt;manager registrar-list 34.66.194.73 34.66.194.74&lt;BR /&gt;manager active-list 34.66.194.74 34.66.194.73&lt;BR /&gt;!&lt;BR /&gt;manager port-list 987&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface management 1&lt;BR /&gt;&amp;nbsp;disable&lt;BR /&gt;!&lt;BR /&gt;interface ve 1&lt;BR /&gt;&amp;nbsp;ip address 190.1.5.51 255.255.0.0&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jun 2021 20:48:59 GMT</pubDate>
    <dc:creator>david_levine</dc:creator>
    <dc:date>2021-06-25T20:48:59Z</dc:date>
    <item>
      <title>Configure 802.1x auth on 7150 stacks</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/Configure-802-1x-auth-on-7150-stacks/m-p/30807#M1707</link>
      <description>&lt;P style="margin: 0;"&gt;I need to get 802.1x auth configured on all of our ICX 7150 switches, and am reading through the documentation trying to learn. I came across this in the Security Guide/Flexible Authentication section:&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;"Before authentication is enabled on a port, the port can belong to any VLAN, including the system default VLAN. The only restriction is that the port cannot be a part of any VLAN as untagged."&amp;nbsp;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Am I understanding this correctly? No ports can have an untagged VLAN on them at all?&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;As it stands today, all ports on our "IDF" or "Access" switches (switches that provide the end users ports to plug into), are unstagged on VLAN 1 and tagged on VLAN 333.&amp;nbsp; VLAN 1 is what our main IP network is on... client machines, some servers, etc. VLAN 333 is used for our Mitel phone system and IP phone sets. So, if a Mitel IP phone is plugged into a port, it will get some DHCP options passed to it that will get it on the 333 VLAN (tagged) and the computer pass-through port on the back of the phone stays untagged on VLAN 1.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;I am having a hard time understanding how this will work if we can't have VLAN 1 untagged on our ports?&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Here is an example switch config currently;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;ver 08.0.95bT213&lt;BR /&gt;!&lt;BR /&gt;stack unit 1&lt;BR /&gt;&amp;nbsp; module 1 icx7150-24p-poe-port-management-module&lt;BR /&gt;&amp;nbsp; module 2 icx7150-2-copper-port-2g-module&lt;BR /&gt;&amp;nbsp; module 3 icx7150-4-sfp-plus-port-40g-module&lt;BR /&gt;&amp;nbsp; stack-port 1/3/1&lt;BR /&gt;&amp;nbsp; stack-port 1/3/3&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;global-stp&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;vlan 1 name DEFAULT-VLAN by port&lt;BR /&gt;&amp;nbsp;router-interface ve 1&lt;BR /&gt;&amp;nbsp;spanning-tree&lt;BR /&gt;!&lt;BR /&gt;vlan 25 name Honeywell by port&lt;BR /&gt;&amp;nbsp;tagged ethe 1/3/1 to 1/3/4&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;vlan 101 name NAC_Corp1_WLAN_101 by port&lt;BR /&gt;&amp;nbsp;tagged ethe 1/1/1 to 1/1/24 ethe 1/3/1 to 1/3/4&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;vlan 106 name NAC_Warehouse_WLAN_106 by port&lt;BR /&gt;&amp;nbsp;tagged ethe 1/1/1 to 1/1/24 ethe 1/3/1 to 1/3/4&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;vlan 107 name NAC_Employee_Phone_WLAN_07 by port&lt;BR /&gt;&amp;nbsp;tagged ethe 1/1/1 to 1/1/24 ethe 1/3/1 to 1/3/4&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;vlan 108 name "Ruckus AP" by port&lt;BR /&gt;&amp;nbsp;tagged ethe 1/3/3&amp;nbsp;&lt;BR /&gt;&amp;nbsp;untagged ethe 1/1/21&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;vlan 333 name "voip vlan" by port&lt;BR /&gt;&amp;nbsp;tagged ethe 1/1/1 to 1/1/20 ethe 1/1/22 to 1/1/24 ethe 1/3/1 to 1/3/4&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;enable aaa console&lt;BR /&gt;hostname "IDF EXP OFFICE"&lt;BR /&gt;ip dns server-address 8.8.8.8&lt;BR /&gt;ip route 0.0.0.0/0 190.1.200.235&lt;BR /&gt;!&lt;BR /&gt;telnet timeout 10&lt;BR /&gt;no telnet server&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ntp&lt;BR /&gt;&amp;nbsp;server ntp.ruckuswireless.com&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;manager registrar&lt;BR /&gt;manager registrar-list 34.66.194.73 34.66.194.74&lt;BR /&gt;manager active-list 34.66.194.74 34.66.194.73&lt;BR /&gt;!&lt;BR /&gt;manager port-list 987&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface management 1&lt;BR /&gt;&amp;nbsp;disable&lt;BR /&gt;!&lt;BR /&gt;interface ve 1&lt;BR /&gt;&amp;nbsp;ip address 190.1.5.51 255.255.0.0&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 20:48:59 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/Configure-802-1x-auth-on-7150-stacks/m-p/30807#M1707</guid>
      <dc:creator>david_levine</dc:creator>
      <dc:date>2021-06-25T20:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: Configure 802.1x auth on 7150 stacks</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/Configure-802-1x-auth-on-7150-stacks/m-p/30808#M1708</link>
      <description>&lt;P style="margin: 0;"&gt;Hi David,&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Hope you are doing Great!!!&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;you can change default vlan to any other vlan using the command from config mode:&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;con t&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;default-vlan-id 100&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;write memory&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;But you also need to consider your network design if you are using Cisco and using native vlan.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Hope this helps&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Thanks&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Hashim&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 23:05:35 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/Configure-802-1x-auth-on-7150-stacks/m-p/30808#M1708</guid>
      <dc:creator>hashim_bharooc1</dc:creator>
      <dc:date>2021-06-25T23:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Configure 802.1x auth on 7150 stacks</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/Configure-802-1x-auth-on-7150-stacks/m-p/30809#M1709</link>
      <description>&lt;P style="margin: 0;"&gt;Hi David,&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;On ICX, A port can be untagged on any single vlan and tagged to multiple vlans. This is the thumb rule. You can open a support case to have a quick call with support staff to clarify your questions as well.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Thanks&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Jijo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 03:54:35 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/Configure-802-1x-auth-on-7150-stacks/m-p/30809#M1709</guid>
      <dc:creator>jijo_panangat</dc:creator>
      <dc:date>2021-07-07T03:54:35Z</dc:date>
    </item>
  </channel>
</rss>

