Configuring A Guest Vlan; Configuring An Auth-Fail Vlan - H3C S5120-EI Series Operation Manual

Hide thumbs Also See for S5120-EI Series:
Table of Contents

Advertisement

Configuring a Guest VLAN

Configuration prerequisites
Enable 802.1X.
Create the VLAN to be specified as the guest VLAN.
To configure a port-based guest VLAN, make sure that the port access control method is
portbased, and the 802.1X multicast trigger function is enabled.
To configure a MAC-based guest VLAN, make sure that the port access control method is
macbased and the MAC VLAN function is enabled on the port. For the MAC VLAN configuration,
refer to VLAN Configuration in the Access Volume.
Configuration procedure
Follow these steps to configure a guest VLAN:
To do...
Enter system view
Configure the
guest VLAN
for specified
or all ports
Different ports can be configured with different guest VLANs, but a port can be configured with only
one guest VLAN.
You cannot configure both the guest VLAN function and the free IP function in EAD fast
deployment.
If you configure both 802.1X authentication and MAC authentication on a port and specify an MGV
for each authentication method, the MGV for the 802.1X authentication method will take effect. For
information about MGV for MAC authentication, refer to MAC Authentication Configuration in the
Security Volume.
The generated MGV entry for a MAC address will overwrite the existing blocked-MAC entry for the
MAC address. But if the port is disabled by the intrusion protection function, the MGV cannot take
effect. For description on the intrusion protection function of disabling a port, refer to Port Security
Configuration in the Security Volume.
If the data flows from a user-side device carry VLAN tags, and 802.1X and guest VLAN are enabled
on the access port, you are recommended to configure different VLAN IDs for the voice VLAN, the
default port VLAN, and the guest VLAN of 802.1X.

Configuring an Auth-Fail VLAN

Use the command...
system-view
In system
dot1x guest-vlan guest-vlan-id
view
[ interface interface-list ]
interface interface-type
In Ethernet
interface-number
interface view
dot1x guest-vlan vlan-id
1-17
Remarks
Required
Use either approach.
By default, a port is configured
with no guest VLAN.

Advertisement

Chapters

Table of Contents
loading

Table of Contents