Users Guide

show dot1x cos-mapping interface
show dot1x interface
show dot1x profile
dot1x critical-vlan
Configure critical-VLAN for users or devices when authentication server is not reachable.
Syntax
[no] dot1x critical-vlan vlan-id
Parameters
vlan-id
Enter the VLAN identifier. The VLAN-ID range is from 1 to 4094.
Defaults Not Configured.
Command Modes
INTERFACE
INTERFACE (BATCH MODE)
Command History
This guide is platform-specific. For command information about other platforms, refer to the relevant Dell
Networking OS Command Line Reference Guide.
The following is a list of the Dell Networking OS version history for this command.
Version Description
9.10(0.0) Introduced on the S3100 series, S4048–ON, S4048–ON, S4810, S4820T, S5000, S6000,
S6000–ON, the Configuration Terminal Batch mode on C9010, Z9100–ON, and Z9500.
9.9(0.0) Introduced on the C9000 Series.
Usage Information
The dot1x critical-vlan command configures critical VLAN for the interface. If the authentication server
is not reachable or not responding, the authenticator places the port or the supplicant in critical VLAN within the
first attempt.
Use this command in Interface Batch mode to configure critical VLAN for users in a dual-homing setup.
Example
Dell(conf)#show dot1x interface ten gigabit ethernet 0/41
802.1x information on Te 0/41:
-----------------------------
Dot1x Status: Enable
Port Control: AUTO
Port Auth Status: AUTHORIZED (CRITICAL-VLAN)
Re-Authentication: Enable
Untagged VLAN id: 400
Guest VLAN: Enable
Guest VLAN id: 400
Auth-Fail VLAN: Enable
Auth-Fail VLAN id: 400
Auth-Fail Max-Attempts: 3
Critical VLAN: Enable
Critical VLAN id: 400
Mac-Auth-Bypass: Disable
Mac-Auth-Bypass Only: Disable
Tx Period: 30 seconds
Quiet Period: 60 seconds
ReAuth Max: 2
Supplicant Timeout: 30 seconds
Server Timeout: 30 seconds
Re-Auth Interval: 60 seconds
Max-EAP-Req: 2
Host Mode: SINGLE_HOST
Auth PAE State: Authenticated
Backend State: Idle
802.1X
157