問題文
Two workstations fail to reach the network through 802.1X-enabled access interfaces on the same switch. The first one has no 802.1X client software and never answers EAP messages, and neither MAC RADIUS authentication nor captive portal is configured on its interface. The second one answers EAP messages but offers credentials that the RADIUS server turns down. A guest VLAN is configured on both interfaces, and the help desk expects to find both workstations in it. What happens?
選択肢
- The first workstation alone is moved into the guest VLAN, because every workstation that offers wrong credentials is handled by the server-reject VLAN instead.
- Both workstations are moved into the guest VLAN, because the guest VLAN is the fallback for every end device that the RADIUS server has not returned an Access-Accept message for, whatever the reason was.
- Neither workstation reaches the guest VLAN, because a guest VLAN is read only after the server-fail action of the interface has been tried.
- Only the second workstation is moved into the guest VLAN, because an end device that never answers EAP messages is treated as non-responsive and is held in the unauthorized state until MAC RADIUS authentication is added to the interface it uses.