ZyXEL GS1910-24 User Guide - Page 41

How to Set Up a Guest VLAN with IEEE 802.1x Authentication

Page 41 highlights

Chapter 5 Tutorials 5.5 How to Set Up a Guest VLAN with IEEE 802.1x Authentication All ports on the Switch are in VLAN 1 by default. Say you enable IEEE 802.1x authentication on ports 1 to 8. Clients that connect to these ports should provide the correct user name and password in order to access the ports. You want to assign clients that connect to ports 1, 2 or 3 to a guest VLAN (200 for example) when they fail to authenticate with the authentication server. In this guest VLAN, clients can surf the Internet through a gateway attached to port 10, but are not allowed to access other network resources, such as the mail server or local data base. VLAN 1 Guest VLAN 200 Ports 1, 2, 3 and 10 Internet 5.5.1 Creating a VLAN for Port which is not IEEE 802.1x enabled Follow the steps below to configure port 10 as a member of VLAN 200. 1 Access the web configurator through the Switch's port which is not in VLAN 200. 2 Click Configuration > VLANs > VLAN Membership in the navigation panel. Click Add New VLAN to create VLAN2. 3 Enter 200 in the VLAN ID field and enter a descriptive name (VLAN200 for example) in the VLAN Name field for this VLAN. 4 Configure port 10 to be a permanent member of the VLAN. GS1910/XGS1910 Series User's Guide 41

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76

Chapter 5 Tutorials
GS1910/XGS1910 Series User’s Guide
41
5.5
How to Set Up a Guest VLAN with IEEE 802.1x
Authentication
All ports on the Switch are in VLAN 1 by default. Say you enable IEEE 802.1x authentication on
ports 1 to 8. Clients that connect to these ports should provide the correct user name and password
in order to access the ports. You want to assign clients that connect to ports 1, 2 or 3 to a guest
VLAN (200 for example) when they fail to authenticate with the authentication server. In this guest
VLAN, clients can surf the Internet through a gateway attached to port 10, but are not allowed to
access other network resources, such as the mail server or local data base.
5.5.1
Creating a VLAN for Port which is not IEEE 802.1x enabled
Follow the steps below to configure port 10 as a member of VLAN 200.
1
Access the web configurator through the Switch’s port which is not in VLAN 200.
2
Click
Configuration
>
VLANs > VLAN Membership
in the navigation panel. Click
Add New
VLAN
to create VLAN2.
3
Enter 200 in the
VLAN ID
field and enter a descriptive name (VLAN200 for example) in the
VLAN
Name
field for this VLAN.
4
Configure port 10 to be a permanent member of the VLAN.
Internet
Guest VLAN 200
Ports 1, 2, 3 and 10
VLAN 1