Guest VLAN
107
16 802.1X Network Access Control
Guest VLAN
The Guest VLAN feature allows a switch to provide a distinguished service to unauthenticated
users. This feature provides a mechanism to allow visitors and contractors to have network
access to reach external network with no ability to surf internal LAN.
When a client that does not support 802.1X is connected to an unauthorized port that is
802.1X-enabled, the client does not respond to the 802.1X requests from the switch.
Therefore, the port remains in the unauthorized state, and the client is not granted access to the
network. If a guest VLAN is configured for that port, then the port is placed in the configured
guest VLAN and the port is moved to the authorized state, allowing access to the client.
Client devices that are 802.1X-supplicant-enabled authenticate with the switch when they are
plugged into the 802.1X-enabled switch port. The switch verifies the credentials of the client
by communicating with an authentication server. If the credentials are verified, the
authentication server informs the switch to 'unblock' the switch port and allows the client
unrestricted access to the network; i.e., the client is a member of an internal VLAN.
Guest VLAN Supplicant mode is a global configuration for all the ports on the switch. When a
port is configured for Guest VLAN in this mode, if a client fails authentication on the port, the
client is assigned to the guest VLAN configured on that port. The port is assigned a Guest
VLAN ID and is moved to the authorized status. Disabling the supplicant mode does not clear
the ports that are already authorized and assigned Guest VLAN IDs.
Configuring the Guest VLAN by Using the CLI
To enable the Guest VLAN Supplicant Mode, use the
dot1x guest-vlan supplicant
command in Global Config mode.
To configure a VLAN as guest VLAN on a per port basis, enter the Interface Config mode for
the port and use the
dot1x guest-vlan
<vlan-id>
command.
Содержание UNIFIED WIRED & WIRELESS ACCESS SYSTEM...
Страница 2: ...2 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 12: ...12 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 14: ...14 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 32: ...32 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 40: ...40 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 44: ...44 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 55: ...Web Examples 55 6 IGMP Snooping Figure 19 IGMP Snooping Multicast Router VLAN Configuration Page ...
Страница 56: ...56 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 66: ...66 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 84: ...84 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 90: ...90 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 103: ...Web Examples 103 15 Access Control Lists ACLs Figure 57 Attach IP ACL to an Interface ...
Страница 110: ...110 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 123: ...Web Examples 123 18 Port Security Figure 70 Port Security Violation Status ...
Страница 124: ...124 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 129: ...RADIUS Configuration Examples 129 19 RADIUS Figure 73 Configuring the RADIUS Server ...
Страница 137: ...TACACS Configuration Example 137 20 TACACS Figure 82 Set the User Login TACACS ...
Страница 138: ...138 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 146: ...146 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 166: ...166 2001 2011 D Link Corporation All Rights Reserved Configuration Guide Figure 109 DHCP Filter Binding Information ...
Страница 176: ...176 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...
Страница 183: ...Web Interface Examples 183 28 Simple Network Time Protocol SNTP Figure 115 Summer Time Configuration Page ...
Страница 184: ...184 2001 2011 D Link Corporation All Rights Reserved Configuration Guide ...