173
<Sysname> system-view
[Sysname] interface ten-gigabitethernet 1/0/1
[Sysname-Ten-GigabitEthernet1/0/1] dot1x auth-fail vlan 100
Related commands
display dot1x
dot1x auth-fail vsi
Use
dot1x auth-fail vsi
to configure an 802.1X Auth-Fail VSI on a port.
Use
undo dot1x auth-fail vsi
to restore the default.
Syntax
dot1x auth-fail vsi authfail-vsi-name
undo dot1x auth-fail vsi
Default
No 802.1X Auth-Fail VSI exists on a port.
Views
Layer 2 Ethernet interface view
Layer 2 aggregate interface view
Predefined user roles
network-admin
mdc-admin
Parameters
authfail-vsi-name
: Specifies the name of the 802.1X Auth-Fail VSI on the port, a case-sensitive string
of 1 to 31 characters.
Usage guidelines
An 802.1X Auth-Fail VSI accommodates users that have failed 802.1X authentication for any reason
other than unreachable servers. Users in the 802.1X Auth-Fail VSI can access a limited set of
network resources in the VXLAN associated with this VSI.
You can configure only one 802.1X Auth-Fail VSI on a port. The 802.1X Auth-Fail VSIs on different
ports can be different.
On a port, the 802.1X Auth-Fail VSI configuration is mutually exclusive with the 802.1X guest VLAN,
802.1X Auth-Fail VLAN, and 802.1X critical VLAN settings.
Examples
# Configure VSI
vsiuser
as the Auth-Fail VSI on Ten-GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface ten-gigabitethernet 1/0/1
[Sysname-Ten-GigabitEthernet1/0/1] dot1x auth-fail vsi vsiuser
Related commands
display dot1x