<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=ALCATEL_-_802.1x_Troubleshoot</id>
	<title>ALCATEL - 802.1x Troubleshoot - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=ALCATEL_-_802.1x_Troubleshoot"/>
	<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=ALCATEL_-_802.1x_Troubleshoot&amp;action=history"/>
	<updated>2026-05-02T18:47:32Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.2</generator>
	<entry>
		<id>https://it-arts.net/index.php?title=ALCATEL_-_802.1x_Troubleshoot&amp;diff=985&amp;oldid=prev</id>
		<title>Admin: Text replacement - &quot;Category:Wiki&quot; to &quot;Category:Wiki

&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;
&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=ALCATEL_-_802.1x_Troubleshoot&amp;diff=985&amp;oldid=prev"/>
		<updated>2026-01-17T08:11:48Z</updated>

		<summary type="html">&lt;p&gt;Text replacement - &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;&amp;quot; to &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; &amp;quot;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 08:11, 17 January 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Platforms :&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Platforms :&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
	<entry>
		<id>https://it-arts.net/index.php?title=ALCATEL_-_802.1x_Troubleshoot&amp;diff=313&amp;oldid=prev</id>
		<title>Admin: Text replacement - &quot;Category:Post-It&quot; to &quot;Category:Wiki&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=ALCATEL_-_802.1x_Troubleshoot&amp;diff=313&amp;oldid=prev"/>
		<updated>2025-12-08T17:22:38Z</updated>

		<summary type="html">&lt;p&gt;Text replacement - &amp;quot;&lt;a href=&quot;/index.php?title=Category:Post-It&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;Category:Post-It (page does not exist)&quot;&gt;Category:Post-It&lt;/a&gt;&amp;quot; to &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;&amp;quot;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:22, 8 December 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Post-It&lt;/del&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Wiki&lt;/ins&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Platforms :&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Platforms :&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
	<entry>
		<id>https://it-arts.net/index.php?title=ALCATEL_-_802.1x_Troubleshoot&amp;diff=130&amp;oldid=prev</id>
		<title>Admin at 14:31, 21 October 2024</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=ALCATEL_-_802.1x_Troubleshoot&amp;diff=130&amp;oldid=prev"/>
		<updated>2024-10-21T14:31:18Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Category:Post-It]]&lt;br /&gt;
&lt;br /&gt;
Platforms :&lt;br /&gt;
* OmniSwitch AOS Release 8 Network Configuration Guide December 2019&lt;br /&gt;
* OmniSwitch OS6860/OS6900/OS10K Troubleshooting Guide&lt;br /&gt;
&lt;br /&gt;
802.1x debug :&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
show unp user authentication-type 802.1x&lt;br /&gt;
show unp user detail&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== show unp ==&lt;br /&gt;
&lt;br /&gt;
Platforms Supported : OmniSwitch 6900&lt;br /&gt;
&lt;br /&gt;
Displays the Universal Network Profile (UNP) configuration for the switch :&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
show unp [unp_name]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* unp_name&lt;br /&gt;
** The name of the UNP.&lt;br /&gt;
&lt;br /&gt;
By default, the configuration for all UNPs is displayed.&lt;br /&gt;
&lt;br /&gt;
Enter a UNP name with this command to display information for a specific UNP.&lt;br /&gt;
Examples :&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
-&amp;gt; show unp&lt;br /&gt;
Name Vlan Policy List Name&lt;br /&gt;
--------------------------------+----+-------------------------------&lt;br /&gt;
Sales 100 list1&lt;br /&gt;
Finance 1000 list2&lt;br /&gt;
&lt;br /&gt;
-&amp;gt; show unp Finance&lt;br /&gt;
Name Vlan Policy List Name&lt;br /&gt;
--------------------------------+----+-------------------------------&lt;br /&gt;
Finance 1000 list2&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== show unp user ==&lt;br /&gt;
&lt;br /&gt;
Displays the MAC addresses learned on a UNP port and the UNP that was used for classification.&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
show unp user [[user_name] | [slot/port[-port2] count]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* user_name&lt;br /&gt;
** The name of a specific device (for example, the device MAC address).&lt;br /&gt;
&lt;br /&gt;
* slot/port[-port2]&lt;br /&gt;
** The slot and port number (3/1). Use a hyphen to specify a range of ports (3/1-8).&lt;br /&gt;
&lt;br /&gt;
* count&lt;br /&gt;
** Displays the number of UNP users.&lt;br /&gt;
&lt;br /&gt;
By default, information is displayed for all learned devices.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Examples ===&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
-&amp;gt; show unp user&lt;br /&gt;
Total users: 3&lt;br /&gt;
User Auth&lt;br /&gt;
Port Username Mac address IP Vlan UNP Status&lt;br /&gt;
----+-----------------+-----------------+---------+----+-------+-------&lt;br /&gt;
1/1 00:00:00:00:00:01 00:00:00:00:00:01 10.0.0.1 10 Sales Active&lt;br /&gt;
1/1 00:80:df:00:00:02 00:80:df:00:00:02 10.0.0.2 20 Finance Active&lt;br /&gt;
1/2 00:80:df:00:00:03 00:80:df:00:00:03 20.0.0.5 30 - Block&lt;br /&gt;
&lt;br /&gt;
-&amp;gt; show unp user 00:00:00:00:00:01&lt;br /&gt;
Port : 01/20,&lt;br /&gt;
Mac-address : 00:00:00:00:00:01,&lt;br /&gt;
IP : 14.15.16.17,&lt;br /&gt;
Vlan : 300,&lt;br /&gt;
User Network Profile : unp3,&lt;br /&gt;
Login Timestamp : 04/01/1970 18:45:26,&lt;br /&gt;
Authentication Type : Mac authentication,&lt;br /&gt;
Authentication Status : Authenticated,&lt;br /&gt;
Classification Source : RADIUS - Server UNP&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
-&amp;gt; show unp user 1/1-5&lt;br /&gt;
Total users: 3&lt;br /&gt;
User Auth&lt;br /&gt;
Port UsernameMac address IP Vlan UNP Status&lt;br /&gt;
----+-----------------+-----------------+---------+----+-------+-----&lt;br /&gt;
1/1 00:00:00:00:00:01 00:00:00:00:00:01 10.0.0.1 10 Sales Active&lt;br /&gt;
1/1 00:80:df:00:00:02 00:80:df:00:00:02 10.0.0.2 20 Finance Active&lt;br /&gt;
1/2 00:80:df:00:00:03 00:80:df:00:00:03 20.0.0.5 30 - Block&lt;br /&gt;
-&amp;gt; show unp user 1/1-5 count&lt;br /&gt;
Total users: 3&lt;br /&gt;
-&amp;gt; show unp user count&lt;br /&gt;
Total users: 3&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Verifying the UNP Port Configuration ==&lt;br /&gt;
&lt;br /&gt;
Use the show unp port config command to display the UNP port configuration. For example:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
-&amp;gt; show unp port 1/1/10 config&lt;br /&gt;
Port 1/1/10&lt;br /&gt;
Port-Type = BRIDGE,&lt;br /&gt;
Redirect Port Bounce = Disabled,&lt;br /&gt;
802.1x authentication = Enabled,&lt;br /&gt;
802.1x Pass Alternate Profile = -,&lt;br /&gt;
802.1x Bypass = Disabled,&lt;br /&gt;
802.1x failure-policy = default,&lt;br /&gt;
Mac-auth allow-eap = -,&lt;br /&gt;
Mac authentication = Enabled,&lt;br /&gt;
Mac Pass Alternate Profile = -,&lt;br /&gt;
Classification = Enabled,&lt;br /&gt;
Trust-tag = Enabled,&lt;br /&gt;
Default Profile = -,&lt;br /&gt;
Port Domain Num = 0,&lt;br /&gt;
AAA Profile = -,&lt;br /&gt;
Port Template = bridgeDefaultPortTemplate,&lt;br /&gt;
Port Control Direction = Both,&lt;br /&gt;
Egress Flooding = Not Allowed,&lt;br /&gt;
Admin State = Enabled,&lt;br /&gt;
Dynamic Service = -,&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How It Works ==&lt;br /&gt;
&lt;br /&gt;
Dynamic SA Mode - MACsec with Dynamic SAK using MACsec Key Agreement (MKA) Protocol.&lt;br /&gt;
&lt;br /&gt;
The MKA, as described in IEEE 802.1X-2010, is an extension to 802.1X, which provides the required&lt;br /&gt;
session keys and manages the required encryption keys used by the underlying MACsec protocol. The&lt;br /&gt;
MKA protocol allows peer discovery with confirmation of mutual authentication and sharing of&lt;br /&gt;
MACsec secret keys to protect data exchanged by the peers.&lt;br /&gt;
&lt;br /&gt;
There are two modes of provisioning connectivity association keys (CAK/CKN) between two MACsec&lt;br /&gt;
endpoints. OmniSwitch supports the following:&lt;br /&gt;
&lt;br /&gt;
* Dynamic SAK using Pre-Shared Key (PSK)&lt;br /&gt;
** MACsec using Static Connectivity Association Key (static-CAK) using PSK&lt;br /&gt;
&lt;br /&gt;
* Dynamic SAK using Extensible Authentication Protocol (EAP)&lt;br /&gt;
** MACsec using Dynamic Connectivity Association Key (dynamic-CAK) using EAP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Dynamic SAK using EAP ==&lt;br /&gt;
&lt;br /&gt;
This mode is applicable for securing link between a host and a switch end-points. Following are some&lt;br /&gt;
configuration guidelines when MACsec is set to dynamic SA mode using RADIUS server:&lt;br /&gt;
IEEE 802.1X-2010 defines the way that MACsec can be used in conjunction with authentication to&lt;br /&gt;
provide secure port-based access control using authentication.&lt;br /&gt;
&lt;br /&gt;
IEEE 802.1X authenticates the endpoint and transmits the necessary cryptographic keying material to both sides. Using the master keys derived&lt;br /&gt;
from the IEEE 802.1X authentication, MACsec can establish an encrypted link on the LAN, thereby&lt;br /&gt;
helping ensure the security of the authenticated session.&lt;br /&gt;
&lt;br /&gt;
* When configuring MACsec on a switch-to-host link, the MKA session establishment between the&lt;br /&gt;
switch and the host is initiated once the 802.1x authentication is successful on the port. The 802.1x&lt;br /&gt;
authentication method must be either EAP-TLS or PEAP authentication framework.&lt;br /&gt;
&lt;br /&gt;
* The MKA keys are received from the RADIUS server. A successful 802.1x-authentication results in&lt;br /&gt;
MKA keys (MSK and Session-Id), which will be passed from the RADIUS server to the switch and&lt;br /&gt;
from RADIUS server to the host in an independent authentication transaction. The master key will then&lt;br /&gt;
be passed between the switch and the host to create a MACsec secured connection. The CAK and CKN&lt;br /&gt;
is derived from MSK and the EAP session ID.&lt;br /&gt;
&lt;br /&gt;
*  CAK and CKN needs to be derived both at the host and the switch, hence 802.1x-authentication using&lt;br /&gt;
EAP-TLS must be used as mutual authentication protocol for MACsec Dynamic mode.&lt;br /&gt;
After deriving CAK/CKN, the switch acts as the key server. It generates a random SAK, which is sent to&lt;br /&gt;
the client. The client is never a key server and can only interact with a single MKA entity, the key server.&lt;br /&gt;
After key derivation and generation, the switch sends periodic transports to the client at a default interval&lt;br /&gt;
of two seconds&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Statically Assigning Service Profiles for Silent Devices ==&lt;br /&gt;
&lt;br /&gt;
When a MAC address is learned on a UNP port and classified into a service profile, a SAP is dynamically&lt;br /&gt;
created based on the parameter values of the service profile. Once the MAC address associated with the&lt;br /&gt;
dynamic SAP ages out, the SAP ages out as well. This poses a problem for silent devices connected to&lt;br /&gt;
UNP access ports; when the device goes idle and the dynamic SAP ages out, the silent device no longer&lt;br /&gt;
receives broadcast or multicast packets to wake the device.&lt;br /&gt;
&lt;br /&gt;
To accommodate silent devices, assign a service profile to the UNP port. When the profile is assigned to&lt;br /&gt;
the UNP port, a SAP is dynamically created based on the service parameter values defined for the profile.&lt;br /&gt;
This action is automatically triggered even if a MAC address has not been learned on the port.&lt;br /&gt;
&lt;br /&gt;
The SAP that is created when a service profile is assigned to a UNP port is a persistent SAP that will not&lt;br /&gt;
age out when any MAC addresses learned on the SAP age out; the SAP continues to receive broadcast and&lt;br /&gt;
multicast packets for the silent device even if there are no MAC addresses learned on the SAP.&lt;br /&gt;
&lt;br /&gt;
Consider the following guidelines when statically assigning a service profile for silent devices:&lt;br /&gt;
&lt;br /&gt;
* Make sure the specified UNP profile name already exists in the switch configuration and is mapped to&lt;br /&gt;
an SPB, VXLAN, L2 GRE, or static service.&lt;br /&gt;
&lt;br /&gt;
* Profiles mapped to SPB, VXLAN, or static services are configured as static profiles on UNP access&lt;br /&gt;
ports.&lt;br /&gt;
&lt;br /&gt;
* Profiles mapped to an L2 GRE service are configured as static profiles on UNP bridge ports.&lt;br /&gt;
&lt;br /&gt;
* More than one SPB or VXLAN service profile can be statically assigned to the same UNP access port,&lt;br /&gt;
but mixing service types on the same port is not supported. For example, configure only SPB service&lt;br /&gt;
profiles or only VXLAN service profiles for the same access port.&lt;br /&gt;
&lt;br /&gt;
* There can only be one L2 GRE service profile statically assigned to a UNP bridge port.&lt;br /&gt;
To assign a service profile to a UNP port, use the unp port profile command. For example, the following&lt;br /&gt;
commands configure and assign service profile “static-spb1” to UNP access port 1/4/31:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
-&amp;gt; unp profile static-spb1&lt;br /&gt;
-&amp;gt; unp profile static-spb1 map service spb tag-value 10 isid 1500 bvlan 500&lt;br /&gt;
-&amp;gt; unp port 1/4/31 port-type access&lt;br /&gt;
-&amp;gt; unp port 1/4/31 profile static-spb1&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
UNP service profile “static-spb1” is mapped to SPB service parameters. When this profile is assigned to&lt;br /&gt;
UNP access port 1/4/31, a dynamic SPB SAP is automatically created to process traffic on that port. The&lt;br /&gt;
1/4/31 port SAP never ages out and is only taken down when the profile assignment is removed from the&lt;br /&gt;
port.&lt;br /&gt;
&lt;br /&gt;
To remove a profile assignment from a UNP port, use the no form of the unp port profile command. For&lt;br /&gt;
example:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
-&amp;gt; no unp port 1/4/31 profile static-spb1&lt;br /&gt;
Use the show unp port profile command to verify the UNP static profile configuration. For example:&lt;br /&gt;
-&amp;gt; show unp port profile&lt;br /&gt;
Port Profile&lt;br /&gt;
-------+----------------&lt;br /&gt;
1/4/31 static-spb1&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To verify that a dynamic service and SAP was created automatically when a service profile is assigned to&lt;br /&gt;
a UNP port, use the show service and show service ports commands. For example:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
-&amp;gt; show service&lt;br /&gt;
Legend: * denotes a dynamic object&lt;br /&gt;
All Service Info&lt;br /&gt;
Svc SAP Bind&lt;br /&gt;
ServiceId Type Adm Oper Stats Count Count Description&lt;br /&gt;
----------+-----+----+----+-----+------+------+---------------------------------&lt;br /&gt;
32768* SPB Up Down N 1 0 Dynamic Service isid=1500 for UNP&lt;br /&gt;
Configuring Access Guardian Configuring Port-Based Network Access Control&lt;br /&gt;
OmniSwitch AOS Release 8 Network Configuration Guide December 2019 page 29-57&lt;br /&gt;
-&amp;gt; show service 32768 ports&lt;br /&gt;
Legend: (*) dyn unicast object (+) remote mcast object (#) local mcast object&lt;br /&gt;
SPB Service 32768 (Dynamic Service isid=1500 for UNP)&lt;br /&gt;
Admin : Up, Oper : Down, Stats : N, Mtu : 9194, VlanXlation : N,&lt;br /&gt;
ISID : 1500, BVlan: 500, MCast-Mode: Headend, Tx/Rx : 0/0, RemoveIngTag: N&lt;br /&gt;
Sap Trusted:Priority/ Sap Description /&lt;br /&gt;
Identifier Adm Oper Stats Sdp SystemId:BVlan Intf Sdp SystemName&lt;br /&gt;
---------------+----+----+-----+--------------------+-------+-------------------&lt;br /&gt;
sap:1/4/31:10* Up Down N Y:x 1/4/31 Dynamic SAP for UNP&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For more information about the commands described in this section, see the “Access Guardian&lt;br /&gt;
Commands” chapter and the “Service Manager Commands” chapter in the OmniSwitch AOS Release 8&lt;br /&gt;
CLI Reference Guide.&lt;br /&gt;
&lt;br /&gt;
Statically Assigning VLANs for Silent Devices ==&lt;br /&gt;
&lt;br /&gt;
When a MAC address is learned on a UNP bridge port and classified into a VLAN profile, a VLAN-port&lt;br /&gt;
association is dynamically created between the port and the VLAN mapped to the profile. The UNP port&lt;br /&gt;
becomes a member of that VLAN. However, when the MAC address ages out, the VLAN-port association&lt;br /&gt;
also ages out and the UNP port is no longer a member of that VLAN. This is problematic for silent&lt;br /&gt;
devices as they will no longer receive broadcast packets forwarded on the VLAN to wake the device.&lt;br /&gt;
To accommodate silent devices, statically assign a VLAN to the UNP bridge port. Doing so will&lt;br /&gt;
automatically create a VLAN-port association between the port and VLAN that will not age out even if&lt;br /&gt;
there are no MAC addresses learned on the port; the UNP bridge port continues to receive broadcast&lt;br /&gt;
packets for any silent device that is connected to the port.&lt;br /&gt;
&lt;br /&gt;
Consider the following guidelines when configuring a static VLAN for a UNP bridge port:&lt;br /&gt;
&lt;br /&gt;
* Static VLANs are only configurable on UNP bridge ports (UNP access ports are not supported).&lt;br /&gt;
&lt;br /&gt;
* Statically assigning a VLAN as an untagged or tagged VLAN for the UNP port is supported.&lt;br /&gt;
&lt;br /&gt;
* When a VLAN is assigned to a UNP bridge port, the port goes into a forwarding state for egress traffic&lt;br /&gt;
associated with the VLANs assigned to the port. This automatically occurs even when there is no MAC&lt;br /&gt;
address learned on the UNP port in the assigned VLANs and regardless of the direction value (in or&lt;br /&gt;
both) set for the port.&lt;br /&gt;
&lt;br /&gt;
To configure an untagged or tagged VLAN assignment for a UNP bridge port, use the unp vlan&lt;br /&gt;
command. For example, the following command assigns VLAN 100 as an untagged static VLAN&lt;br /&gt;
assignment for UNP port 1/4/45:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
-&amp;gt; unp port 1/4/45 vlan 100&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To specify a tagged VLAN assignment, use the tagged parameter with the unp vlan command. For&lt;br /&gt;
example:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
-&amp;gt; unp port 1/4/45 vlan 100 tagged&lt;br /&gt;
Configuring a UNP port or link aggregate with an untagged and tagged VLAN-port association is allowed&lt;br /&gt;
as long as the untagged and tagged VLANs are different. For example, the following commands configure&lt;br /&gt;
an untagged and tagged VLAN assignment for the same UNP bridge port:&lt;br /&gt;
-&amp;gt; unp port 1/4/45 vlan 100&lt;br /&gt;
-&amp;gt; unp port 1/4/45 vlan 200 tagged&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Usefull Links ==&lt;br /&gt;
&lt;br /&gt;
* https://support.alcadis.nl/Support_files/Alcatel-Lucent/OmniSwitch//OS6900/Manuals/OS6900%20AOS%207.2.1%20R01/OS6900%20AOS%207.2.1%20R01%20CLI%20Reference%20Guide.pdf&lt;br /&gt;
&lt;br /&gt;
* https://support.alcadis.nl/Support_files/Alcatel-Lucent/OmniSwitch//OS6900/Technotes/7X%208X%20Troubleshooting%20Guide.pdf&lt;br /&gt;
&lt;br /&gt;
* https://support.alcadis.nl/Support_files/Alcatel-Lucent/OmniSwitch//OS6865/Manuals/OS6865%20AOS%208.6.R02/OS6865%20AOS%208.6.R02%20Network%20Configuration%20Guide.pdf&lt;br /&gt;
&lt;br /&gt;
* https://www.alcatelunleashed.com/viewtopic.php?t=31635&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>