Command Manual (For Soliton) – 802.1x-System Guard
H3C S3100 Series Ethernet Switches
Chapter 1 802.1x Configuration Commands
1-9
z
If the switch receives no response from the port after sending
EAP-Request/Identity packets to the port for the maximum number of times, the
switch will add the port to the guest VLAN.
z
Users in a guest VLAN can access the guest VLAN resources without 802.1x
authentication. However, they have to pass the 802.1x authentication to access
the external resources.
In system view,
z
If you do not provide the
interface-list
argument, these two commands apply to all
the ports of the switch.
z
If you specify the
interface-list
argument, these two commands apply to the
specified ports.
In Ethernet port view, the
interface-list
argument is not available and these two
commands apply to only the current Ethernet port.
Caution:
z
The Guest VLAN function is available only when the switch operates in the
port-based authentication mode.
z
Only one Guest VLAN can be configured on a switch.
z
The Guest VLAN function is unavailable when the
dot1x dhcp-launch
command is
executed on the switch, because the switch does not send authentication request
packets in this case.
Example
# Configure the switch to operate in the port-based authentication mode.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] dot1x port-method portbased
# Enable the Guest VLAN function for all the ports.
[Sysname] dot1x guest-vlan 1
1.1.6 dot1x handshake
Syntax
dot1x handshake enable
undo dot1x handshake enable