Yamaha 10G SWR2310-28GT/18GT/10G Command Reference - Page 146

Set dynamic VLAN, 3.13 Set the guest VLAN

Page 146 highlights

146 | Command Reference | Interface control During Web authentication, the supplicant's authentication state is shifted to unauthorized at the timing of reauthentication. To use this command, you must enable the port authentication function for the applicable interface. (dot1x port-control command, auth-mac enable command, auth-web enable command) [Example] Enable re-authenticatio of LAN port #1. SWR2310(config)#interface port1.1 SWR2310(config-if)#auth reauthentication 5.3.12 Set dynamic VLAN [Syntax] auth dynamic-vlan-creation no auth dynamic-vlan-creation [Initial value] no auth dynamic-vlan-creation [Input mode] interface mode [Description] Sets dynamic VLAN for the applicable interface. If this is executed with the "no" syntax, the dynamic VLAN is disabled. For interfaces on which dynamic VLAN is enabled, the associated VLAN is actively changed based on the property (TunnelPrivate-Group-ID) specified by the RADIUS server. [Note] This command can be specified only for both LAN/SFP port and logical interface. Changing the settings for this command will make the authentication state return to the default. When using dynamic VLAN in multi-supplicant mode, the VLAN can be specified for individual supplicants. When using dynamic VLAN in multi-host, the VLAN ID applied by the first supplicant will be applied to supplicants from the second onwards. To use this command, you must enable the port authentication function for the applicable interface. (dot1x port-control command, auth-mac enable command, auth-web enable command) [Example] Enable dynamic VLAN on LAN port #1. SWR2310(config)#interface port1.1 SWR2310(config-if)#auth dynamic-vlan-creation 5.3.13 Set the guest VLAN [Syntax] auth guest-vlan vlan-id no auth guest-vlan [Parameter] vlan-id : VLAN ID for guest VLAN [Initial value] no auth guest-vlan [Input mode] interface mode [Description] If the supplicant connected to the applicable interface is unauthorized or if authorization has failed, this specifies the guest VLAN to which the supplicant is associated. If this command is executed with the "no" syntax, the guest VLAN setting is deleted. [Note] This command can be specified only for both LAN/SFP port and logical interface.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278

During Web authentication, the supplicant's authentication state is shifted to unauthorized at the timing of reauthentication.
To use this command, you must enable the port authentication function for the applicable interface. (
dot1x port-control
command,
auth-mac enable
command,
auth-web enable
command)
[Example]
Enable re-authenticatio of LAN port #1.
SWR2310(config)#interface port1.1
SWR2310(config-if)#auth reauthentication
5.3.12 Set dynamic VLAN
[Syntax]
auth
dynamic-vlan-creation
no
auth
dynamic-vlan-creation
[Initial value]
no auth dynamic-vlan-creation
[Input mode]
interface mode
[Description]
Sets dynamic VLAN for the applicable interface.
If this is executed with the "no" syntax, the dynamic VLAN is disabled.
For interfaces on which dynamic VLAN is enabled, the associated VLAN is actively changed based on the property (Tunnel-
Private-Group-ID) specified by the RADIUS server.
[Note]
This command can be specified only for both LAN/SFP port and logical interface.
Changing the settings for this command will make the authentication state return to the default.
When using dynamic VLAN in multi-supplicant mode, the VLAN can be specified for individual supplicants.
When using dynamic VLAN in multi-host, the VLAN ID applied by the first supplicant will be applied to supplicants from the
second onwards.
To use this command, you must enable the port authentication function for the applicable interface. (
dot1x port-control
command,
auth-mac enable
command,
auth-web enable
command)
[Example]
Enable dynamic VLAN on LAN port #1.
SWR2310(config)#interface port1.1
SWR2310(config-if)#auth dynamic-vlan-creation
5.3.13 Set the guest VLAN
[Syntax]
auth
guest-vlan
vlan-id
no
auth
guest-vlan
[Parameter]
vlan-id
:
<1-4094>
VLAN ID for guest VLAN
[Initial value]
no auth guest-vlan
[Input mode]
interface mode
[Description]
If the supplicant connected to the applicable interface is unauthorized or if authorization has failed, this specifies the guest
VLAN to which the supplicant is associated.
If this command is executed with the "no" syntax, the guest VLAN setting is deleted.
[Note]
This command can be specified only for both LAN/SFP port and logical interface.
146
| Command Reference | Interface control