Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

802.1x with /21 subnet


I am currently deploying 802.1x using following devices:

XP - HP Procurve - Cisco ACS - Active Directory

I am able to forward dynamic vlan id to employe and consultant after authentication.

Bit how to deal with big site having a large number of people?

Without 802.1x, they are splitted in class C subnet to restrict obvious big subnet limitation like broadcast domain.

How to assign a pool of vlans to one group of users instead of 1 vlan?

Thanks for your help.Stephane


Re: 802.1x with /21 subnet

802.1X authenticated ports are assigned to a VLAN that is based on the username of the host that is connected to the port. VLAN assignments work with the RADIUS server, which has a database of username-to-VLAN mappings. After a successful 802.1X authentication of the port, the RADIUS server sends the VLAN in which the user needs to be given access.

Refer to

Cisco Employee

Re: 802.1x with /21 subnet

Architecturally, performing the VLAN Assignment by name mitigates this concern and allows for flexibility in this regard. 802.1X should not require you to build a specific VLAN/VTP architecture for subnetting. Ideally, it should work with what you already have. This is supported on all Cisco Catalyst switches.