The topology is shown above, client has to pass the mac authentication, get the vlan from Radius Server, and then access the network.
When S5700 is in version V200R003C01, the client and get through. But after ugrading to V200R005C00, the client cannot be authenticated successfully.
1. Check interface which connects to the client, the interface is negotiated to access
<S5700>display interface GigabitEthernet0/0/21
GigabitEthernet0/0/21 current state : DOWN
Line protocol current state : DOWN
Switch Port, Link-type : access(negotiated)
2. Change the link-type to hybrid manually, the MAC authentication goes through.
port link-type hybrid
In this scenario, the link-type must be hybrid to obtain VLAN information dynamically from Radius Server after client was authenticated successfully.
In version V200R003C01, the link-type of interface is hybrid by default. But in version V200R005C00, the link-type of interface is negotiated. If it is negotiated to accss, the interface cannot obtain VLAN information dynamically.
1. The link-type must be hybrid when the interface need to support dynamic VLAN
2. The change should be indicated in upgrading guide