Got a somewhat complex setup requested for 802.1x on some HP procurves, and I am not sure if there is an ability top satisfy all the criteria. The is for my access switches.
Each switchport will be hosting multiple devices. Mainly a phone (that can do 802.1x) and PC behind that. Many of the PC's will have multiple virtual machines hosted on them, that will require a level of network access. We have 3 VLANs to use:
VLAN 100 - Data. Require port authentication. PC's will be utilizing supplicant to authenticate for VLAN access
VLAN 200 - Voice. It has been requested that while the phones can do 802.1x, they do not want to set this up on each phone, as the password will be a manual process
VLAN 300 - Guest. Is the node does not authenticate, it will be placed in a guest network.
My biggest issue seems to be around the phone/vocie VLAN. If it could be done by MAC, all phones will have same leading 6 in their MAC address.