•
Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X guest VLAN on a port.
The assignment makes sure the port can correctly process incoming VLAN-tagged traffic.
•
When you configure multiple security features on a port, follow the guidelines in
Table 7 Relationships of the 802.1X guest VLAN and other security features
Feature
Super VLAN
802.1X Auth-Fail VLAN on
a
port
that
MAC-based
control
Port intrusion protection
actions on a port that
performs
access control
Configuration prerequisites
Before you configure an 802.1X guest VLAN, complete the following tasks:
•
Create the VLAN to be specified as the 802.1X guest VLAN.
•
If the 802.1X-enabled port performs MAC-based access control, perform the following
operations for the port:
Configure the port as a hybrid port.
Enable MAC-based VLAN on the port. For more information about the MAC-based VLAN
feature, see Layer 2—LAN Switching Configuration Guide.
Assign the port to the 802.1X guest VLAN as an untagged member.
Configuration procedure
To configure an 802.1X guest VLAN:
Step
1.
Enter system view.
2.
Enter
view.
3.
Configure the 802.1X guest
VLAN on the port.
Enabling 802.1X guest VLAN assignment delay
IMPORTANT:
This feature is available in Release 1121 and later.
This feature delays assigning an 802.1X-enabled port to the 802.1X guest VLAN when 802.1 X
authentication is triggered by packets from unknown MAC addresses on the port.
Relationship description
You cannot specify a VLAN as both a super VLAN
and an 802.1X guest VLAN.
performs
The 802.1X Auth-Fail VLAN has a higher priority
access
than the 802.1X guest VLAN.
The 802.1X guest VLAN feature has higher
priority than the block MAC action.
The 802.1X guest VLAN feature has lower priority
MAC-based
than the shutdown port action of the port intrusion
protection feature.
Command
system-view
Ethernet
interface
interface
interface-number
dot1x guest-vlan guest-vlan-id
interface-type
88
Table
Reference
See
Layer
Switching
Configuration
Guide.
See
"802.1X
manipulation."
See
"Configuring
security."
Remarks
N/A
N/A
By default, no 802.1X guest VLAN
is configured on any port.
7.
2—LAN
VLAN
port
Need help?
Do you have a question about the FlexNetwork 5510 HI Series and is the answer not in the manual?