76
Guest VLAN
The 802.1X guest VLAN on a port accommodates users who have not performed 802.1X
authentication. Once a user in the guest VLAN passes 802.1X authentication, it is removed from the
guest VLAN and can access authorized network resources.
The access device handles VLANs on an 802.1X-enabled port based on its 802.1X access control
method.
On a port that performs port-based access control:
Authentication status
VLAN manipulation
A user has not passed
802.1X authentication.
The device assigns the 802.1X guest VLAN to the port as the PVID. All
802.1X users on this port can access resources only in the guest VLAN.
If no 802.1X guest VLAN is configured, the access device does not perform
any VLAN operation.
A user in the 802.1X guest
VLAN fails 802.1X
authentication.
If an 802.1X Auth-Fail VLAN (see "
") is available, the device
assigns the Auth-Fail VLAN to the port as the PVID. All users on this port can
access only resources in the Auth-Fail VLAN.
If no Auth-Fail VLAN is configured, the PVID on the port is still the 802.1X
guest VLAN. All users on the port are in the guest VLAN.
A user in the 802.1X guest
VLAN passes 802.1X
authentication.
•
The device assigns the authorization VLAN of the user to the port as the
PVID, and it removes the port from the 802.1X guest VLAN. After the
user logs off, the initial PVID of the port is restored.
•
If the authentication server does not authorize a VLAN, the initial PVID
applies. The user and all subsequent 802.1X users are assigned to the
initial port VLAN. After the user logs off, the port VLAN remains
unchanged.
NOTE:
The initial PVID of an 802.1X-enabled port refers to the PVID used by the
port before the port is assigned to any 802.1X VLANs.
Critical VLAN
The 802.1X critical VLAN on a port accommodates 802.1X users who have failed authentication
because none of the RADIUS servers in their ISP domain is reachable. The critical VLAN feature
takes effect when 802.1X authentication is performed only through RADIUS servers. If an 802.1X
user fails local authentication after RADIUS authentication, the user is not assigned to the critical
VLAN.
The access device handles VLANs on an 802.1X-enabled port based on its 802.1X access control
method.
On a port that performs port-based access control:
Authentication status
VLAN manipulation
A user that has not been assigned to any
VLAN fails 802.1X authentication
because all the RADIUS servers are
unreachable.
The device assigns the critical VLAN to the port as the PVID.
The 802.1X user and all subsequent 802.1X users on this port
can access resources only in the 802.1X critical VLAN.
A user in the 802.1X critical VLAN fails
authentication because all the RADIUS
servers are unreachable.
The critical VLAN is still the PVID of the port, and all 802.1X
users on this port are in this VLAN.