Comware

 View Only
Expand all | Collapse all

HPE 1920S JL382A switch do not assign dynamic VLANs to ports after MAC authentication

This thread has been viewed 9 times
  • 1.  HPE 1920S JL382A switch do not assign dynamic VLANs to ports after MAC authentication

    Posted Apr 23, 2026 05:27 AM

    I have several switches in my institution, specifically HPE 1920S JL381A and JL382A. All have been updated to the latest software version PD.02.23.

    The problem I'm having is that the switches cannot assign dynamic VLANs to the ports after MAC authentication.

    I use a RADIUS server from my domain controller, Microsoft NPS, and it works very well on other HP models like the v1910 and v1920, but it doesn't work on this OfficeConnect 1920s model. It receives the acceptance from the NPS server, with the VLAN attribute all correct, but it cannot assign the VLAN to the port.

    The error that appears in the History Log Summary:
    Dot1x Radius Accept Process - VLAN [160] Assignment Failure, failed to authenticate MAC Authentication Client.

    The error in the system log or Buffered Log:
    DOT1X Error in assigning VLAN 160 to port/client.

    Can anyone help me, or is there an HPE mediator?



    -------------------------------------------


  • 2.  RE: HPE 1920S JL382A switch do not assign dynamic VLANs to ports after MAC authentication

    Posted 4 days ago

    Worth flagging first: the 1920S isn't Comware, despite the board this landed on. It's the PD-code web managed line, separate software from the 1910/1920 where your NPS setup works, so parity between them was never a given.

    More useful, there's a defect with your exact symptom. CR_0000248798, "switch fails to perform dynamic VLAN assignment after MAC authentication", is listed as fixed in the 02.09, 02.13 and 02.15 release notes. Three fixes for one CR usually means it keeps coming back. You're past all of them on 02.23, so this is worth taking to HPE with those two log lines attached, since that's the detail they'll ask for first.

    Before that, check the config gates. Guest VLAN ID has to be 0 or MAC Authentication won't enable at all, control mode has to be MAC-Based with the Authenticator role, and VLAN 160 needs to exist with the port included unless Dynamic VLAN Creation Mode is on. Turn Monitor Mode off for a clean test, it passes failures through instead of enforcing. Also try flipping MAC Authentication Type between EAP-MD5 and PAP to match the NPS policy.



    ------------------------------
    Dustin Burns

    @Worldcom Exchange, Inc.


    If my post was useful accept solution and/or give kudos
    ------------------------------