732
C
50: 802.1
HAPTER
Guest VLAN
Configuration
Example
C
X
ONFIGURATION
# Enable 802.1x globally.
[Sysname] dot1x
# Enable 802.1x for port GigabitEthernet 1/0/1.
[Sysname] interface GigabitEthernet 1/0/1
[Sysname-GigabitGigabitEthernet1/0/1] dot1x
[Sysname-GigabitGigabitEthernet1/0/1] quit
# Set the port access control method. (Optional. The default answers the
requirement.)
[Sysname] dot1x port-method macbased interface GigabitEthernet 1/0/1
Network requirements
As shown in Figure 220:
A host is connected to port GigabitEthernet 1/0/1 of the switch and must pass
■
802.1x authentication to access the Internet.
The authentication server run RADIUS and is in VLAN 2.
■
The update server, which is in VLAN 10, is for client software download and
■
upgrade.
Port GigabitEthernet 1/0/2 of the switch, which is in VLAN 5, is for accessing
■
the Internet.
As shown in Figure 221:
On port GigabitEthernet 1/0/1, enable 802.1x and set VLAN 10 as the guest
■
VLAN.
As shown in Figure 222:
Authenticated supplicants are assigned to VLAN 5 and permitted to access the
■
Internet.