Users Guide

Table Of Contents
Security Commands 948
reinitialize—Re-authenticate hosts, potentially into the critical data
VLAN.
authorize—Hosts on the data VLAN are switched to the critical data
VLAN without re-authentication.
vlan-id—The critical data VLAN identifier.
Default Configuration
By default, critical data VLAN capability is not enabled.
Command Mode
Interface (Ethernet) Configuration mode
User Guidelines
The command configures the critical data VLAN ID. If the VLAN ID is not
specified, the port PVID is used as the critical data VLAN ID.
The critical data VLAN capability allows hosts to authenticate when no
RADIUS server is reachable. This allows potentially limited access to the
network via VLAN configuration. The dead-server (all RADIUS servers
marked dead) actions are configured per interface using this command.
When the dead-server action is configured to reinitialize, the switch triggers
802.1X re-authentication of all authenticated hosts on the port. Hosts on the
voice VLAN, unauthenticated VLAN (authentication failed hosts) or guest
VLAN are not disturbed. During re-authentication, if all the servers are still
dead, the hosts are authenticated successfully into the critical data VLAN.
When the dead server action is configured to authorize, the switch authorizes
the authenticated supplicants into the critical data VLAN. Hosts on a
RADIUS assigned VLAN, voice VLAN, unauthenticated VLAN or guest
VLAN are not disturbed. Hosts authorized on the port PVID are re-
authorized into the critical VLAN.
Command History
Syntax added in version 6.6 firmware.