User Manual

Table Of Contents
For interfaces on which dynamic VLAN is enabled, the associated VLAN is actively changed based on the property (Tunnel-
Private-Group-ID) specified by the RADIUS server.
[Note]
This command can be specified only for both LAN/SFP+ port and logical interface.
Changing the settings for this command will make the authentication state return to the default.
When using dynamic VLAN in multi-supplicant mode, the VLAN can be specified for individual supplicants.
When using dynamic VLAN in multi-host, the VLAN ID applied by the first supplicant will be applied to supplicants from the
second onwards.
To use this command, you must enable the port authentication function for the applicable interface. (dot1x port-control
command, auth-mac enable command, auth-web enable command)
[Example]
Enable dynamic VLAN on LAN port #1.
SWP2(config)#interface port1.1
SWP2(config-if)#auth dynamic-vlan-creation
5.3.15 Set the guest VLAN
[Syntax]
auth guest-vlan vlan-id
no auth guest-vlan
[Parameter]
vlan-id : <1-4094>
VLAN ID for guest VLAN
[Initial value]
no auth guest-vlan
[Input mode]
interface mode
[Description]
If the supplicant connected to the applicable interface is unauthorized or if authorization has failed, this specifies the guest
VLAN to which the supplicant is associated.
If this command is executed with the "no" syntax, the guest VLAN setting is deleted.
[Note]
This command can be specified only for both LAN/SFP+ port and logical interface.
Changing the settings for this command will make the authentication state return to the default.
To use this command, you must enable the port authentication function for the applicable interface. (dot1x port-control
command, auth-mac enable command)
This command cannot be set when Web authentication is enabled.
[Example]
This specifies guest VLAN #10 for LAN port #1.
SWP2(config)#interface port1.1
SWP2(config-if)#auth guest-vlan 10
5.3.16 Suppression period settings following failed authentication
[Syntax]
auth timeout quiet-period time
no auth timeout quiet-period
[Parameter]
time : <1-65535>
Period during which communication with a supplicant is refused after authentication fails (seconds)
Command Reference | Interface control | 157