No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.

Knowledge Base

MAC authentication failed due to link-type negotiated to access

Publication Date:  2014-07-29  |   Views:  496  |   Downloads:  0  |   Author:  p00441838  |   Document ID:  EKB1000047417


Issue Description

The topology is shown above, client has to pass the mac authentication, get the vlan from Radius Server, and then access the network.
When S5700 is in version V200R003C01, the client and get through. But after ugrading to V200R005C00, the client cannot be authenticated successfully.

Alarm Information


Handling Process

1. Check interface which connects to the client, the interface is negotiated to access
<S5700>display interface GigabitEthernet0/0/21
GigabitEthernet0/0/21 current state : DOWN
Line protocol current state : DOWN
Switch Port, Link-type : access(negotiated)
2. Change the link-type to hybrid manually, the MAC authentication goes through.
interface GigabitEthernet0/0/21
port link-type hybrid

Root Cause

In this scenario, the link-type must be hybrid to obtain VLAN information dynamically from Radius Server after client was authenticated successfully. 
In version V200R003C01, the link-type of interface is hybrid by default. But in version V200R005C00, the link-type of interface is negotiated. If it is negotiated to accss, the interface cannot obtain VLAN information dynamically.


1. The link-type must be hybrid when the interface need to support dynamic VLAN
2. The change should be indicated in upgrading guide