VLAN authentication limitations

VLAN authentication is subject to the following limitations:

  • VLAN authentication is only supported on Dot1q-encapsulated ports. It is not supported on NULL or QinQ-encapsulated ports.

  • VLAN authentication only uses the outermost VLAN tag received in the packets. Packets with more than one tag are processed only if the outermost tag matches the SAP tag.

  • Restrictions on processing of SAP tags also apply to VLAN authenticated frames. VLAN authentication does not change the current behavior for frames mapped to different SAPs and services.

  • VLAN range SAPs are not supported on a port with VLAN authentication enabled.

  • Dot1q default SAPs configured on a port with Dot1q encapsulation do not support VLAN authentication.

  • Dot1q explicit null SAPs can be configured on a port with Dot1q encapsulation, which requires authentication of null-tagged EAPOL frames.