Cisco WS-C3560E-48PD-SF Command Reference - Page 124
You can con any active VLAN except an Remote Switched Port Analyzer RSPAN VLAN,
View all Cisco WS-C3560E-48PD-SF manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 124 highlights
dot1x guest-vlan Chapter 2 Catalyst 3560 Switch Cisco IOS Commands With Cisco IOS Release 12.2(25)SE and later, the switch maintains the EAPOL packet history. If another EAPOL packet is detected on the interface during the lifetime of the link, the guest VLAN feature is disabled. If the port is already in the guest VLAN state, the port is returned to the unauthorized state, and authentication is restarted. The EAPOL history is reset upon loss of link. Entering the dot1x guest-vlan supplicant global configuration command disables this behavior. Any number of non-IEEE 802.1x-capable clients are allowed access when the switch port is moved to the guest VLAN. If an IEEE 802.1x-capable client joins the same port on which the guest VLAN is configured, the port is put into the unauthorized state in the user-configured access VLAN, and authentication is restarted. Guest VLANs are supported on IEEE 802.1x ports in single-host or multiple-hosts mode. You can configure any active VLAN except an Remote Switched Port Analyzer (RSPAN) VLAN, a primary private VLAN, or a voice VLAN as an IEEE 802.1x guest VLAN. The guest VLAN feature is not supported on internal VLANs (routed ports) or trunk ports; it is supported only on access ports. After you configure a guest VLAN for an IEEE 802.1x port to which a DHCP client is connected, you might need to get a host IP address from a DHCP server. You can change the settings for restarting the IEEE 802.1x authentication process on the switch before the DHCP process on the client times out and tries to get a host IP address from the DHCP server. Decrease the settings for the IEEE 802.1x authentication process (dot1x timeout quiet-period and dot1x timeout tx-period interface configuration commands). The amount to decrease the settings depends on the connected IEEE 802.1x client type. Examples This example shows how to specify VLAN 5 as an IEEE 802.1x guest VLAN: Switch(config-if)# dot1x guest-vlan 5 This example shows how to set 3 as the quiet time on the switch, to set 15 as the number of seconds that the switch waits for a response to an EAP-request/identity frame from the client before resending the request, and to enable VLAN 2 as an IEEE 802.1x guest VLAN when an IEEE 802.1x port is connected to a DHCP client: Switch(config-if)# dot1x timeout quiet-period 3 Switch(config-if)# dot1x timeout tx-period 15 Switch(config-if)# dot1x guest-vlan 2 This example shows how to enable the optional guest VLAN behavior and to specify VLAN 5 as an IEEE 802.1x guest VLAN: Switch(config)# dot1x guest-vlan supplicant Switch(config)# interface gigabitethernet0/1 Switch(config-if)# dot1x guest-vlan 5 You can verify your settings by entering the show dot1x [interface interface-id] privileged EXEC command. Related Commands Command dot1x show dot1x [interface interface-id] Description Enables the optional guest VLAN supplicant feature. Displays IEEE 802.1x status for the specified port. 2-92 Catalyst 3560 Switch Command Reference 78-16405-05