dot1x force-authorized vlan
When the RADIUS authentication method is used, this command forcibly changes the
status of a terminal to authentication authorized and assigns an authenticated VLAN if the
RADIUS server does not respond or a request to a RADIUS server fails due to route failure.
Input format
To set or change information:
dot1x force-authorized vlan
To delete information:
no dot1x force-authorized
Input mode
(config-if)
Parameters
<VLAN ID>
Sets the authenticated VLAN ID to be assigned when forced authentication is
authorized.
1.
Default value when this parameter is omitted:
This parameter cannot be omitted.
2.
Range of values:
See Specifiable values for parameters. Note that the default
cannot be set.
Default behavior
None
Impact on communication
None
When the change is applied
The change is applied immediately after setting values are changed.
Notes
1.
All IEEE 802.1X settings take effect when the
command is set.
2.
See Table 22-1 Configuration commands and IEEE 802.1X authentication modes for
the authentication mode in which the command's settings are operable.
3.
Set a VLAN ID for which
command.
4.
Be especially careful when using this functionality, as it might pose a security
problem.
5.
This command takes effect when the following condition is met:
<VLAN ID>
dot1x system-auth-control
mac-based
(MAC VLAN) has been set in the
dot1x force-authorized vlan
VLAN (VLAN ID = 1)
vlan
381