85
Enhancements
Release L.11.08 Enhancements
System Location and Contact String Size Increase
Configuring a System Contact and Location for the Switch
Both the
system-contact
and the
system-location
fields now allow up to 255 characters.
Syntax:
snmp-server [contact <
system-contact
>] [location <
system-location
>]
For example, enter “George_Johnson” as the system contact, and “North-Data-Room” as the location.
Enter the
show system-information
command to see the names displayed.
Syntax:
aaa port-access gvrp-vlans
(Continued)
2. After you enable dynamic VLAN assignment in an authentication session, it
is recommended that you use the
interface unknown-vlans
command on a per-port
basis to prevent denial-of-service attacks. The
interface unknown-vlans
command
allows you to:
• Disable the port from sending advertisements of existing GVRP-created VLANs
on the switch.
• Drop all GVRP advertisements received on the port.
For more information, refer to the “GVRP” chapter in the Advanced Traffic
Management Guide.
3. If you disable the use of dynamic VLANs in an authentication session using
the
no aaa port-access gvrp-vlans
command, client sessions that were authenticated
with a dynamic VLAN continue and are not deauthenticated.
(This behavior differs form how static VLAN assignment is handled in an
authentication session. If you remove the configuration of the static VLAN used
to create a temporary client session, the 802.1X, MAC, or Web authenticated client
is deauthenticated.)
However, if a RADIUS-configured dynamic VLAN used for an authentication
session is deleted from the switch through normal GVRP operation (for example,
if no GVRP advertisements for the VLAN are received on any switch port),
authenticated clients using this VLAN are deauthenticated.
For information on how static and dynamic VLANs are assigned in a RADIUS-
based 802.1X, MAC, or Web authentication session, refer to the “How RADIUS-
Based Authentication Affects VLAN Operation” section in the “RADIUS Authenti-
cation and Accounting” chapter of the Access Security Guide.