User Manual

Table Of Contents
5.3.12 Set dynamic VLAN
[Syntax]
auth dynamic-vlan-creation
no auth dynamic-vlan-creation
[Initial value]
no auth dynamic-vlan-creation
[Input mode]
interface mode
[Description]
Sets dynamic VLAN for the applicable interface.
If this is executed with the "no" syntax, the dynamic VLAN is disabled.
For interfaces on which dynamic VLAN is enabled, the associated VLAN is actively changed based on the property (Tunnel-
Private-Group-ID) specified by the RADIUS server.
[Note]
This command can be specified only for both LAN/SFP port and logical interface.
Changing the settings for this command will make the authentication state return to the default.
When using dynamic VLAN in multi-supplicant mode, the VLAN can be specified for individual supplicants.
When using dynamic VLAN in multi-host, the VLAN ID applied by the first supplicant will be applied to supplicants from the
second onwards.
To use this command, you must enable the port authentication function for the applicable interface. (dot1x port-control
command, auth-mac enable command, auth-web enable command)
[Example]
Enable dynamic VLAN on LAN port #1.
SWX3220(config)#interface port1.1
SWX3220(config-if)#auth dynamic-vlan-creation
5.3.13 Set the guest VLAN
[Syntax]
auth guest-vlan vlan-id
no auth guest-vlan
[Parameter]
vlan-id : <1-4094>
VLAN ID for guest VLAN
[Initial value]
no auth guest-vlan
[Input mode]
interface mode
[Description]
If the supplicant connected to the applicable interface is unauthorized or if authorization has failed, this specifies the guest
VLAN to which the supplicant is associated.
If this command is executed with the "no" syntax, the guest VLAN setting is deleted.
[Note]
This command can be specified only for both LAN/SFP port and logical interface.
Changing the settings for this command will make the authentication state return to the default.
To use this command, you must enable the port authentication function for the applicable interface. (dot1x port-control
command, auth-mac enable command)
This command cannot be set when Web authentication is enabled.
[Example]
This specifies guest VLAN #10 for LAN port #1.
176 | Command Reference | Interface control