
By default, 802.1x re-authentication is disabled on an interface.
----End
5.3.13 (Optional) Configuring a Guest VLAN for 802.1x
Authentication
Context
When the guest VLAN is enabled, the AR1200-S broadcasts authentication request packets to
all the interfaces enabled with 802.1x authentication. If an interface does not return a response
when the maximum number of re-authentication times is reached, the AR1200-S adds the
interface to the guest VLAN. Users in the guest VLAN can access resources in the guest VLAN
without authentication but must be authenticated when they access external resources.
NOTE
The configured guest VLAN cannot be the default VLAN of the interface.
A super VLAN cannot be configured as a guest VLAN.
If an interface is configured with the guest VLAN, the interface cannot be added to the guest VLAN and
the VLAN configured as the guest VLAN cannot be deleted. Users in the guest VLAN can communicate
with each other.
You can configure a guest VLAN in the system view and in the interface view.
Procedure
l
Configuring a guest VLAN in the system view
1.
Run:
system-view
The system view is displayed.
2.
Run:
dot1x guest-vlan
vlan-id
interface
{
interface-type
interface-number1
[
to
interface-number2
] } &<1-10>
A guest VLAN is configured on an interface.
By default, no guest VLAN is configured on an interface.
l
Configuring a guest VLAN in the interface view
1.
Run:
system-view
The system view is displayed.
2.
Run:
interface
interface-type
interface-number
The interface view is displayed.
3.
Run:
dot1x guest-vlan
vlan-id
A guest VLAN is configured on the interface.
By default, no guest VLAN is configured on an interface.
----End
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
5 NAC Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
109