5.5.1 Configure 802.1x Port Authentication on the Switch
1 Configure 802.1x on all towards users. Do not enable Port
Authentication on ports to the USG, RADIUS-Server, and
Private-Server. To configure Port Authentication, please refer
to the topic: 5.4 How to Configure the Switch and RADIUS
Server to Provide Network Access through 802.1x Port
Authentication.
5.5.2 Configure VLAN for Guest VLAN
1 Configure the VLAN for Guest VLAN (VLAN 100) on Switch.
VLAN 100: Set fixed port: 1, 2, 3, 30; untagged port: 1, 2, 3, 30;
forbidden port: 31, 32; port 30: pvid=100. VLAN 1: Set forbidden
port: 30. For isolating VLAN 1 and 100, please refer to the topic:
2.1 How to configure the switch to separate traffic between
departments.
5.5.3 Configure Guest VLAN for Failed Authentication
1 Go to Menu > Advanced Application > Port Authentication >
802.1x > Guest Vlan. Activate the Guest Vlan on port 1-3 and
type the guest Vlan as 100. Press "Apply".
www.zyxel.com
161/215