Cisco WS-C3560E-48PD-SF Command Reference - Page 123
dot1x guest-vlan
View all Cisco WS-C3560E-48PD-SF manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 123 highlights
Chapter 2 Catalyst 3560 Switch Cisco IOS Commands dot1x guest-vlan dot1x guest-vlan Use the dot1x guest-vlan interface configuration command to specify an active VLAN as an IEEE 802.1x guest VLAN. Use the no form of this command to return to the default setting. dot1x guest-vlan vlan-id no dot1x guest-vlan Syntax Description vlan-id Specify an active VLAN as an IEEE 802.1x guest VLAN. The range is 1 to 4094. Defaults No guest VLAN is configured. Command Modes Interface configuration Command History Release 12.1(19)EA1 12.2(25)SE 12.2(25)SEC Modification This command was introduced. This command was modified to change the default guest VLAN behavior. The usage guidelines were modified. Usage Guidelines You can configure a guest VLAN on one of these switch ports: • A static-access port that belongs to a non-private VLAN. • A private-VLAN port that belongs to a secondary private VLAN. All the hosts connected to the switch port are assigned to private VLANs, regardless whether the posture validation was successful. The switch determines the primary private VLAN by using the primary- and secondary-private-VLAN associations on the switch. For each IEEE 802.1x port on the switch, you can configure a guest VLAN to provide limited services to clients (a device or workstation connected to the switch) not currently running IEEE 802.1x. These users might be upgrading their systems for IEEE 802.1x authentication, and some hosts, such as Windows 98 systems, might not be IEEE 802.1x-capable. When you enable a guest VLAN on an IEEE 802.1x port, the switch assigns clients to a guest VLAN when it does not receive a response to its Extensible Authentication Protocol over LAN (EAPOL) request/identity frame or when EAPOL packets are not sent by the client. Before Cisco IOS Release 12.2(25)SE, the switch did not maintain the EAPOL packet history and allowed clients that failed authentication access to the guest VLAN, regardless of whether EAPOL packets had been detected on the interface. You can use the dot1x guest-vlan supplicant global configuration command to enable this optional behavior. 78-16405-05 Catalyst 3560 Switch Command Reference 2-91