How to Configure
Ports


In Policy Manager, you can specify a port's authentication settings, as well as specify a default role for the port, freeze or unfreeze a port, enable or disable the Drop VLAN Tagged Frames and MAC Locking features, and enable CEP (Convergence End Point) protocols. There are two ways to configure ports:

Instructions on:

Using the Port Configuration Wizard

The Port Configuration Wizard is a series of windows that leads you through all the steps required to configure a port or ports, including setting the port mode, login settings, and default role. Use the Port Configuration Wizard to configure single or multiple ports simultaneously. You must configure and enable authentication on the device before any port authentication settings will take effect (see How to Configure Devices).
  1. From the menu bar, select Tools > Port Configuration Wizard. The Port Configuration Wizard opens.
  2. In the Port Configuration window, select the configurations you wish to perform:
  3. The sequence of windows you see next depends on the selections you made in the Port Configuration window.
      NOTE: Each window provides the option to use the current configuration on the port(s), or set a new configuration. If you select Use Current Configuration on Port(s), the default settings in the window are visible, but are unavailable for entry or editing. Keep in mind that these values do not necessarily reflect the current settings on the port.

    If you have selected to configure Authentication
    All the windows you could see are listed below, but only those related to the Authentication type(s) you selected will actually appear:

    If you have selected General Settings:
    All the windows you could see are listed below, but only those related to the options you selected will actually appear:



  4. In the Port Selection window, you can select the ports you want to include or exclude from this configuration.
      NOTE: For 802.1X devices that do not support Policy (such as the RoamAbout AP3000):
    -- FTM 1 Backplane ports must be excluded from the port selection when configuring this type of device.
    -- The Active/Default Role port mode is not a valid configuration for this type of device. If you are configuring Active/Default Role port mode, these devices must be excluded.
    1. In the Devices field, expand the folders and select the ports you want to configure.
    2. Click Add Include to include the selected ports in this configuration or click Add Exclude to exclude the ports from the configuration. For example, you may want to configure all your 10/100 ports except printer ports. You would select the Pre-Defined Port Group of 10/100 ports and click Add Include. Then you would select a User-Defined Port Group of printer ports and click Add Exclude.
    3. To remove a port from the Include Ports or Exclude Ports fields, select the port and click Remove.
  5. Click Finish. The settings will take effect.

      NOTE: You must configure and enable authentication on the device before any port authentication settings will take effect (see How to Configure Devices).

Using the Port Tabs

Configuring a port using the port tabs consists of selecting a port in the left-panel Network Elements tab, then using the right panel tabs to configure the port. This accomplishes the same things as the Port Configuration Wizard, but also enables you to view the current configuration on the port. To configure authentication for a port in a Pre-Defined Port Group, you must use the Port Configuration Wizard.

Assigning Default Roles to Ports

You can assign a default role to a single port, or to multiple ports. If you set a default role for a port, it is recommended that you enable the Drop VLAN Tagged Frames feature.

Single Port

  1. In the Policy Manager left panel, select the Network Elements tab.
  2. Expand either the Grouped By, Devices folder, or User-Defined Port Group folder and click on the port you want to configure.
  3. In the right-panel Role tab, you can view the default role for the port. Click the Select button to select a new default role. This opens the Selection View, where you can select an existing role or click New to launch the Role Wizard and create a new role. Select the Clear the current default role option to set the default role back to <None>.
  4. Click OK. The default role configuration will take effect unless you have created a new role. Then, you must enforce the role before the default role configuration setting will take effect.

Multiple Ports

There are two ways to assign a default role to multiple ports:

Clearing Default Roles from Ports

You can clear the default role from a single port, or from multiple ports.

Single Port

  1. In the Policy Manager left panel, select the Network Elements tab.
  2. Expand the Grouped By, Devices folder, or User-Defined Port Group folder and click on the port whose default role you want to clear. (Pre-Defined Port Groups do not have their ports listed in the left panel, so you will need to select the port in the right panel Ports tab.)
  3. Right-click the port and select Set Default Role to open the Selection View.
  4. Select the Clear the current default role box.
  5. Click OK.
  NOTE: If you are replacing the current default role with another one, you don't need to clear the current default role. Selecting the new default role and clicking OK clears the previous default role automatically.

Multiple Ports

There are two ways to clear the default role from multiple ports:

Disabling Traffic Classification Rules on Ports

You can create a list of traffic classification rule types to disable on a port using the Disabled Traffic Classification Type section on the port General tab. For example, you could disable the VLAN ID traffic classification type, which would disable Tagged Packet VLAN to Role Mapping on the port.

  1. In the Policy Manager left panel, select the Network Elements tab.
  2. Expand either the Grouped By folder, Devices folder, or User-Defined Port Group folder and click on the port you want to configure.
  3. Select the General tab in the right panel and use the Disabled Traffic Classification Type section to create the list of rules you want to disable.

Enabling CEP Protocol

You can enable and disable CEP protocols for a specific port using the port CEP Access tab. (You can enable CEP protocols for multiple selected ports using the Port Configuration wizard.) In order for CEP to take effect on a port, it must also be enabled at the device level. You can do this using the Device Configuration wizard, or the device CEP tab. See How to Configure CEP for more information.

Enabling Drop VLAN Tagged Frames

When the Drop VLAN Tagged Frames feature is enabled, any packet already tagged with a VLAN coming into the port will be dropped. Usually you would enable this for user ports, and disable it for interswitch ports. See Drop VLAN Tagged Frames for more information.

  WARNING: Enabling this feature on a CDP or Backplane port is likely to result in loss of contact with devices connected through the port.

  1. In the Policy Manager left panel, select the Network Elements tab.
  2. In the Devices, Grouped By, or User-Defined Port Groups folder, select the port you want to configure .
  3. In the right-panel Role tab, go to the Drop VLAN Tagged Frames area and select Enable.
  4. Click Enforce on the toolbar, review the effects of enforcing in the Enforce Preview window if it is enabled, then click Enforce on that window.

Freezing/Unfreezing Ports

See How to Freeze/Unfreeze a Port.

Locking MAC Addresses to Ports

See How to Lock MAC Addresses to Ports.

Setting Port Authentication

You can configure authentication settings for a selected port on the Authentication Configuration tab for the port. Before any port authentication settings will take effect, you must configure and enable authentication on the device (see How to Configure Devices).

  NOTE: In order to configure authentication for a port in a Pre-Defined Port Group, you must use the Port Configuration Wizard.

  1. In the Policy Manager left panel, select the Network Elements tab.
  2. Expand either the Grouped By folder, Devices folder, or User-Defined Port Group folder and click on the port you want to configure.
  3. Select the Authentication Configuration tab in the right panel and make changes as required.

Terminating a Session

Terminating a session causes the port to be re-initialized. The user loses the access rights of the current role on the port and reverts to the access rights specified for unauthenticated behavior on the port, until he or she authenticates again.

With web-based authentication, the user must log in again using the authentication web page after the port re-initializes. With 802.1X authentication on Windows 2000, the user is prompted to log in again after the port re-initializes. With 802.1X authentication on the Windows XP platform, the user is automatically reauthenticated immediately after the port re-initializes, and no login prompt occurs.

You can terminate an active session on a selected port or ports in the Port Usage tab for a device, the devices folder, a device group, a port, or a port group. If sequential multiple ports are selected, only active sessions are terminated. You cannot terminate sessions on frozen ports and you cannot terminate Role Override (IP) or Role Override (MAC) sessions that were created through the CLI (command line interface).

  NOTE: For 802.1X authentication on the Windows XP platform, if you terminate a user's session, the user is automatically reauthenticated, unless there has been a policy change or a change in the user's authentication status (e.g., the user has been removed from the authentication list).

  1. In the Policy Manager left panel, select the Network Elements tab.
  2. Select the right panel Port Usage tab for one of the following left panel selections, depending on the ports whose session(s) you want to terminate:
  3. In the Port Usage tab, select the active sessions you want to terminate, and click Terminate.
  4. Click Yes to confirm that you want to terminate.

Top


Related Information

For information on related concepts: For information on related tasks: For information on related windows: top