91
Configuration procedure
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Configure
an 802.1X
guest VLAN
for one or
more ports.
In system view
dot1x guest-vlan
guest-vlan-id
[
interface
interface-list
]
Required.
Use either approach.
By default, no 802.1X guest
VLAN is configured on any port.
In Ethernet
interface view
interface
interface-type interface-
number
dot1x guest-vlan
guest-vlan-id
Configuring an Auth-Fail VLAN
Configuration guidelines
Follow these guidelines when configuring an 802.1X Auth-Fail VLAN:
•
Configure only one 802.1X Auth-Fail VLAN on a port. The 802.1X Auth-Fail VLANs on different
ports can be different.
•
Assign different IDs for the voice VLAN, default VLAN, and 802.1X Auth-Fail VLAN on a port, so
that the port can correctly process VLAN tagged incoming traffic.
•
You cannot specify a VLAN as both a super VLAN and an 802.1X Auth-Fail VLAN. For more
information, see
Layer 2
—
LAN Switching Configuration Guide
.
Configuration prerequisites
•
Create the VLAN to be specified as the 802.1X Auth-Fail VLAN.
•
If the 802.1X-enabled port performs port-based access control, enable 802.1X multicast trigger.
•
If the 802.1X-enabled port performs MAC-based access control, configure the port as a hybrid
port, enable MAC-based VLAN on the port, and assign the port to the Auth-Fail VLAN as an
untagged member. For more information, see
Layer 2
—
LAN Switching Configuration Guide
.
To configure an Auth-Fail VLAN:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter Ethernet interface view.
interface
interface-type interface-
number
—
3.
Configure the Auth-Fail VLAN
on the port.
dot1x auth-fail vlan
authfail-vlan-
id
Required.
By default, no Auth-Fail VLAN is
configured.