90
•
If the 802.1X-enabled port performs MAC-based access control, perform the following
operations for the port:
{
Configure the port as a hybrid port.
{
Enable MAC-based VLAN on the port. For more information about the MAC-based VLAN
feature, see
Layer 2—LAN Switching Configuration Guide
.
{
Assign the port to the 802.1X critical VLAN as an untagged member.
Configuration procedure
To configure an 802.1X critical VLAN:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Ethernet interface
view.
interface interface-type
interface-number
N/A
3.
Configure the 802.1X critical
VLAN on the port.
dot1x critical vlan
vlan-id
By default, no 802.1X critical
VLAN is configured.
4.
(Optional.) Send an
EAP-Success packet to a
client when the 802.1X client
user is assigned to the
802.1X critical VLAN on the
port.
dot1x critical eapol
By default, the device sends an
EAP-Failure packet to a client
when the 802.1X client user is
assigned to the 802.1X critical
VLAN on the port.
Enabling 802.1X critical voice VLAN
This feature assigns the access port of a voice user to the 802.1X critical voice VLAN if the voice
user fails authentication because all the RADIUS servers are unreachable. The feature does not take
effect if the voice user has been in the 802.1X Auth-Fail VLAN.
The critical voice VLAN feature takes effect when 802.1X authentication is performed only through
RADIUS servers.
When a reachable RADIUS server is detected, the device performs the following operations:
•
If MAC-based access control is used, the device removes 802.1X voice users from the critical
voice VLAN. The port sends a unicast EAP-Request/Identity packet to each 802.1X voice user
that was assigned to the critical voice VLAN to trigger authentication.
•
If port-based access control is used, the device removes the port from the critical voice VLAN.
The port sends a multicast EAP-Request/Identity packet to all 802.1X voice users on the port to
trigger authentication.
Configuration prerequisites
Before you enable the 802.1X critical voice VLAN on a port, complete the following tasks:
•
Enable LLDP both globally and on the port.
The device uses LLDP to identify voice users. For information about LLDP, see
Layer 2—LAN
Switching Configuration Guide
.
•
Enable voice VLAN on the port.