
81
•
A super VLAN cannot be set as the guest VLAN. Similarly, a guest VLAN cannot be set as the super
VLAN. For information about super VLAN, see
VLAN
in the
Layer 2 – LAN Switching Configuration
Guide
.
Configuration prerequisites
•
Create the VLAN to be specified as the guest VLAN.
•
To configure a port-based guest VLAN, make sure that the port access control method is
portbased
, and the 802.1X multicast trigger function is enabled.
Configuration procedure
Follow these steps to configure a guest VLAN:
To do…
Use the command…
Remarks
1.
Enter system view
system-view
—
2.
Configure the guest VLAN for
one or more ports
In system view
dot1x guest-vlan
guest-
vlan-id
[
interface
interface-
list
]
Required
Use either approach.
By default, a port is
configured with no
guest VLAN.
In Ethernet
interface view
interface
interface-type
interface-number
dot1x guest-vlan
guest-
vlan-id
Different ports can be configured with different guest VLANs, but a port can be configured with only one
guest VLAN.
Configuring an Auth-Fail VLAN
•
If the traffic from a user-side switch carries VLAN tags and the 802.1X authentication and Auth-Fail VLAN
functions are configured on the access port, you are recommended to configure different VLAN IDs for
the default VLAN of the port, and 802.1X Auth-Fail VLAN. This is to ensure the normal use of the
functions.
•
A super VLAN cannot be set as the Auth-Fail VLAN. Similarly, an Auth-Fail VLAN cannot be set as the
super VLAN. For information about super VLAN, see
VLAN
in the
Layer 2 – LAN Switching Configuration
Guide
.
Configuration prerequisites
•
Create the VLAN to be specified as the Auth-Fail VLAN.
•
To configure a port-based Auth-Fail VLAN, make sure that the port access control method is
portbased
, and the 802.1X multicast trigger function is enabled.