Access Security Guide K/KA/KB.15.15

port-based, untagged VLAN membership assigned for the earliest, currently active client
session.
Therefore, on a port where one or more authenticated client sessions are already running, all
such clients are on the same untagged VLAN. If a RADIUS server subsequently authenticates
a new client, but attempts to re-assign the port to a different, untagged VLAN than the one
already in use for the previously existing, authenticated client sessions, the connection for the
new client will fail.
Overview 353