1-20
To do…
Use the command…
Remarks
Enter system view
system-view
—
In system
view
dot1x guest-vlan guest-vlan-id
[
interface
interface-list
]
interface interface-type
interface-number
Configure the
guest VLAN
for one or
more ports
In Ethernet
interface view
dot1x guest-vlan
guest-vlan-id
Required
Use either approach.
By default, a port is configured
with no guest VLAN.
z
Different ports can be configured with different guest VLANs, but a port can be configured with only
one guest VLAN.
z
The generated MGV entry for a MAC address will overwrite the existing blocked-MAC entry for the
MAC address. But if the port is disabled by the intrusion protection function, the MGV cannot take
effect. For description on the intrusion protection function of disabling a port, refer to
Port Security
Configuration
in the
Security Volume
.
Configuring an Auth-Fail VLAN
z
The Auth-Fail VLAN function and the free IP function in EAD fast deployment are mutually
exclusive on a port.
z
If the traffic from a user-side device carries VLAN tags and the 802.1X authentication and guest
VLAN functions are configured on the access port, you are recommended to configure different
VLAN IDs for the voice VLAN, default VLAN of the port, and 802.1X guest VLAN. This is to ensure
the normal use of the functions.
z
A super VLAN cannot be set as the Auth-Fail VLAN. Similarly, an Auth-Fail VLAN cannot be set as
the super VLAN. For information about super VLAN, refer to
VLAN Configuration
in the
Access
Volume
.
Configuration prerequisites
z
Create the VLAN to be specified as the Auth-Fail VLAN.
z
To configure a port-based Auth-Fail VLAN, make sure that the port access control method is
portbased
, and the 802.1X multicast trigger function is enabled.
z
To configure a MAC-based Auth-Fail VLAN, make sure that the port access control method is
macbased
and the MAC VLAN function is enabled on the port. For the MAC VLAN configuration,
refer to
VLAN Configuration
in the
Access Volume
.
Summary of Contents for S7906E - Switch
Page 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Page 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Page 598: ...ii...
Page 1757: ...4 9...
Page 1770: ...6 4...
Page 2017: ...2 11 Figure 2 3 SFTP client interface...
Page 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...