CLI Guide

NOTE: You can create the Layer 3 portion of a guest VLAN and authentication
fail VLANs regardless if the VLAN is assigned to an interface or not. After an
interface is assigned a guest VLAN (which has an IP address), routing through
the guest VLAN is the same as any other traffic. However, the interface may
join/leave a VLAN dynamically.
Related
Commands
dot1x auth-fail-vlan — Configures an authentication failure VLAN.
dot1x reauthentication — Enables periodic re-authentication of the client.
dot1x reauth-max — Configure the maximum number of times to re-
authenticate a port before it becomes unauthorized.
dot1x host-mode
Enable single-host or multi-host authentication.
Syntax
dot1x host-mode {single-host | multi-host | multi-auth}
Parameters
single-host Enable single-host authentication.
multi-host Enable multi-host authentication.
multi-auth Enable multi-supplicant authentication.
Defaults single-host
Command Modes INTERFACE
Supported Modes Full–Switch
Command History
Version Description
9.9(0.0) Introduced on the FN IOM.
9.2(0.0) Introduced on the MXL 10/40GbE Switch IO Module.
Usage Information
Single-host mode authenticates only one host per authenticator port and drops
all other traffic on the port.
Multi-host mode authenticates the first host to respond to an Identity Request
and then permits all other traffic on the port.
Multi-supplicant mode authenticates every device attempting to connect to the
network on the authenticator port.
154
802.1X