
96
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
3.
Configure the 802.1X critical
VLAN on the port.
dot1x critical vlan
vlan-id
By default, no 802.1X critical
VLAN is configured.
Enabling the 802.1X critical voice VLAN
This feature assigns the access port of a voice user to the 802.1X critical voice VLAN if the voice
user fails authentication because all the RADIUS servers are unreachable. The feature does not take
effect if the voice user has been in the 802.1X Auth-Fail VLAN.
The critical voice VLAN feature takes effect when 802.1X authentication is performed only through
RADIUS servers.
When a reachable RADIUS server is detected, the device performs the following operations:
•
If MAC-based access control is used, the device removes 802.1X voice users from the critical
voice VLAN. The port sends a unicast EAP-Request/Identity packet to each 802.1X voice user
that was assigned to the critical voice VLAN to trigger authentication.
•
If port-based access control is used, the device removes the port from the critical voice VLAN.
The port sends a multicast EAP-Request/Identity packet to all 802.1X voice users on the port to
trigger authentication.
Configuration prerequisites
Before you enable the 802.1X critical voice VLAN on a port, complete the following tasks:
•
Enable LLDP both globally and on the port.
The device uses LLDP to identify voice users. For information about LLDP, see
Layer 2—LAN
Switching Configuration Guide
.
•
Enable voice VLAN on the port.
Configuration procedure
To enable the 802.1X critical voice VLAN feature on a port:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
3.
Enable the 802.1X critical
voice VLAN feature on a
port.
dot1x critical-voice-vlan
By default, the 802.1X critical
voice VLAN feature is disabled on
the port.
Summary of Contents for 10500 series
Page 326: ...312 No duration limit for this SA ...