User's Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
47-20
# Set the link type of the port as access mode.
Switch(Config-If-Ethernet1/0/2)#switch-port mode access
# Set the access control mode on the port as portbased.
Switch(Config-If-Ethernet1/0/2)#dot1x port-method portbased
# Set the access control mode on the port as auto.
Switch(Config-If-Ethernet1/0/2)#dot1x port-control auto
# Set the ports Guest VLAN as 100.
Switch(Config-If-Ethernet1/0/2)#dot1x guest-vlan 100
Switch(Config-If-Ethernet1/0/2)#exit
Using the command of show running-config or show interface ethernet1/0/2, use
rs can check the configuration of Guest VLAN. When there is no online user, no failed
user authentication or no user gets offline successfully, and more authentication-triggeri
ng messages (EAP-Request/Identity) are sent than the upper limit defined, users can c
heck whether the Guest VLAN configured on the port takes effect with the command s
how vlan id 100.
47.3.2 Examples of IPv4 Radius Applications
Fig 3-16 IEEE 802.1x Configuration Example Topology
The PC is connecting to port 1/0/2 of the switch; IEEE 802.1x authentication is en
abled on port1/0/2; the access mode is the default MAC-based authentication. The swit
ch IP address is 10.1.1.2. Any port other than port 1/0/2 is used to connect to RADIU
10.1.1.1
10.1.1.2
Radius Server
10.1.1.3