Owner manual

Chapter 31: 802.1x Port-based Network Access Control
742 Section VIII: Port Security
Here are guidelines that apply to adding VLAN assignments to supplicant
accounts on a RADIUS server:
The VLAN can be either port-based or tagged.
The VLAN must already exist on the switch.
A client can have only one VLAN associated with it on the RADIUS
server.
When a supplicant logs on, the switch port is moved as an untagged
port to the designated VLAN.