User Manual

Table Of Contents
[Initial value]
no auth reauthentication
[Input mode]
interface mode
[Description]
Enables reauthentication of supplicants for the applicable interface.
If this is executed with the "no" syntax, the re-authentication is disabled.
When this setting is enabled, this periodically reauthenticates supplicants that have been successfully authenticated.
The reauthentication interval can be changed using the auth timeout reauth-period command.
[Note]
This command can be specified only for both LAN/SFP port and logical interface.
During IEEE 802.1X authentication, an EAPOL packet is transmitted to the supplicant at the timing for reauthentication to once
again retrieve the user information, and an authentication request is sent to the RADIUS server.
During MAC authentication, the supplicant's MAC address is regarded as a user name and password at the timing for
reauthentication, and a request is sent to the RADIUS server for authentication.
During Web authentication, the supplicant's authentication state is shifted to unauthorized at the timing of reauthentication.
To use this command, you must enable the port authentication function for the applicable interface. (dot1x port-control
command, auth-mac enable command, auth-web enable command)
[Example]
Enable re-authenticatio of LAN port #1.
SWR2311P(config)#interface port1.1
SWR2311P(config-if)#auth reauthentication
5.3.12 Set dynamic VLAN
[Syntax]
auth dynamic-vlan-creation
no auth dynamic-vlan-creation
[Initial value]
no auth dynamic-vlan-creation
[Input mode]
interface mode
[Description]
Sets dynamic VLAN for the applicable interface.
If this is executed with the "no" syntax, the dynamic VLAN is disabled.
For interfaces on which dynamic VLAN is enabled, the associated VLAN is actively changed based on the property (Tunnel-
Private-Group-ID) specified by the RADIUS server.
[Note]
This command can be specified only for both LAN/SFP port and logical interface.
Changing the settings for this command will make the authentication state return to the default.
When using dynamic VLAN in multi-supplicant mode, the VLAN can be specified for individual supplicants.
When using dynamic VLAN in multi-host, the VLAN ID applied by the first supplicant will be applied to supplicants from the
second onwards.
To use this command, you must enable the port authentication function for the applicable interface. (dot1x port-control
command, auth-mac enable command, auth-web enable command)
[Example]
Enable dynamic VLAN on LAN port #1.
SWR2311P(config)#interface port1.1
SWR2311P(config-if)#auth dynamic-vlan-creation
5.3.13 Set the guest VLAN
[Syntax]
auth guest-vlan vlan-id
156 | Command Reference | Interface control