Auth Auth-Fail Vlan - Allied Telesis x310-26FT Command Reference Manual

X310 series stackable access switches for alliedware plus version 5.4.6-1.x
Table of Contents

Advertisement

A
C
UTHENTICATION
OMMANDS
-
AUTH AUTH
FAIL VLAN

auth auth-fail vlan

Overview
Use this command to enable the auth-fail vlan feature on the specified vlan
interface. This feature assigns supplicants (client devices) to the specified VLAN if
they fail port authentication.
Use the no variant of this command to disable the auth-fail vlan feature for a
specified VLAN interface.
auth auth-fail vlan <1-4094>
Syntax
no auth auth-fail vlan
Default
The auth-fail vlan feature is disabled by default.
Mode
Interface Configuration for a static channel, a dynamic (LACP) channel group, or a
switch port; or Authentication Profile mode.
Usage
Use the auth-fail vlan feature when using Web-Authentication instead of the Guest
VLAN feature, when you need to separate networks where one supplicant (client
device) requires authentication and another supplicant does not require
authentication from the same interface.
This is because the DHCP lease time using the Web-Authentication feature is
shorter, and the auth-fail vlan feature enables assignment to a different VLAN if a
supplicant fails authentication.
To enable the auth-fail vlan feature with Web Authentication, you need to set the
Web Authentication Server virtual IP address by using the
ipaddress
When using 802.1X port authentication, use a
the maximum number of login attempts. Three login attempts are allowed by
default for 802.1X port authentication before supplicants trying to authenticate
are moved from the Guest VLAN to the auth-fail VLAN. See the
on page 1557 for command information.
See the
for information about:
Use appropriate ACLs (Access Control Lists) on interfaces for extra security if a
supplicant allocated to the designated auth-fail vlan can access the same network
C613-50103-01 REV A
Parameter
Description
<1-4094>
Assigns the VLAN ID to any supplicants that have failed port
authentication.
command or the
AAA and Port Authentication Feature Overview and Configuration Guide
the auth-fail VLAN feature, which allows the Network Administrator to
separate the supplicants who attempted authentication, but failed, from the
supplicants who did not attempt authentication, and
restrictions regarding combinations of authentication enhancements
working together
Command Reference for x310 Series
AlliedWare Plus™ Operating System - Version 5.4.6-1.x
auth-web-server dhcp ipaddress
dot1x max-auth-fail
auth-web-server
command.
command to set
dot1x max-auth-fail
1587

Advertisement

Table of Contents
loading

This manual is also suitable for:

X310-26fpX310-50fpX310-50ft

Table of Contents