1-7
Description
Use the
dot1x dhcp-launch
command to specify an 802.1x-enabled switch to launch the process to
authenticate a supplicant system when the supplicant system applies for a dynamic IP address through
DHCP.
Use the
undo dot1x dhcp-launch
command to disable an 802.1x-enabled switch from authenticating
a supplicant system when the supplicant system applies for a dynamic IP address through DHCP.
By default, an 802.1x-enabled switch does not authenticate a supplicant system when the latter applies
for a dynamic IP address through DHCP.
Related commands:
display dot1x
.
Examples
# Configure to authenticate a supplicant system when it applies for a dynamic IP address through
DHCP.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] dot1x dhcp-launch
dot1x guest-vlan
Syntax
dot1x guest-vlan
vlan-id
[
interface
interface-list
]
undo dot1x guest-vlan
[
interface
interface-list
]
View
System view, Ethernet port view
Parameters
vlan-id
: VLAN ID of a guest VLAN, in the range 1 to 4094.
interface-list
: Ethernet port list, in the form of
interface-list=
{
interface-type interface-number
[
to
interface-type interface-number
] } &<1-10>, in which
interface-type
specifies the type of an Ethernet
port and
interface-number
is the number of the port. The string “&<1-10>” means that up to 10 port lists
can be provided.
Description
Use the
dot1x guest-vlan
command to enable the guest VLAN function for ports.
Use the
undo dot1x guest-vlan
command to disable the guest VLAN function for ports.
After 802.1x and guest VLAN are properly configured on a port:
z
If the switch receives no response from the port after sending EAP-Request/Identity packets to the
port for the maximum number of times, the switch will add the port to the guest VLAN.
z
Users in a guest VLAN can access the guest VLAN resources without 802.1x authentication.
However, they have to pass the 802.1x authentication to access the external resources.
In system view,
z
If you do not provide the
interface-list
argument, these two commands apply to all the ports of the
switch.
Summary of Contents for 5500-EI PWR
Page 43: ...2 6...
Page 76: ...1 17...
Page 228: ...ii stp transmit limit 1 44 vlan mapping modulo 1 45 vlan vpn tunnel 1 46...
Page 477: ...5 24 Sysname vlan 2 Sysname vlan2 service type multicast...
Page 503: ...2 3 System View return to User View with Ctrl Z Sysname dot1x url http 192 168 19 23...
Page 519: ...iii...
Page 597: ...2 2 security policy server 192 168 0 1 user name format without domain...
Page 648: ...1 9 Examples Clear static ARP entries Sysname reset arp static...
Page 663: ...4 3 Sysname resilient arp interface vlan interface 2...
Page 767: ...1 28 From 12 00 Jan 1 2008 to 12 00 Jun 1 2008...
Page 1111: ...ii xmodem get 3 18...
Page 1314: ...A 44 Z...