Dot1X Guest-Vlan - H3C S5120-SI Series Command Reference Manual

Hide thumbs Also See for S5120-SI Series:
Table of Contents

Advertisement

Local authentication supports PAP and CHAP.
For RADIUS authentication, the RADIUS server must be configured accordingly to support PAP,
CHAP, or EAP authentication.
Related commands: display dot1x.
Examples
# Set the 802.1X authentication method to PAP.
<Sysname> system-view
[Sysname] dot1x authentication-method pap

dot1x guest-vlan

Syntax
In system view:
dot1x guest-vlan guest-vlan-id [ interface interface-list ]
undo dot1x guest-vlan [ interface interface-list ]
In interface view:
dot1x guest-vlan guest-vlan-id
undo dot1x guest-vlan
View
System view, Ethernet interface view
Default Level
2: System level
Parameters
guest-vlan-id: ID of the VLAN to be specified as the guest VLAN, in the range 1 to 4094. It must already
exist.
interface interface-list: Specifies a port list. The interface-list argument is in the format of interface-list =
{ interface-type interface-number [ to interface-type interface-number ] } & <1-10>, where interface-type
represents the port type, interface-number represents the port number, and & <1-10> means that you
can provide up to 10 port indexes/port index lists for this argument. The start port number must be
smaller than the end number and the two ports must be of the same type.
Description
Use the dot1x guest-vlan command to configure the guest VLAN for specified or all ports.
Use the undo dot1x guest-vlan command to remove the guest VLAN(s) configured for specified or all
ports.
By default, a port is configured with no guest VLAN.
A guest VLAN can be a port-based guest VLAN (PGV) or a MAC-based guest VLAN (MGV), depending
on the port access control method.
Currently, on the switch, a guest VLAN can be only a port-based guest VLAN (PGV).
Note that:
1-7

Advertisement

Table of Contents
loading

Table of Contents