(Optional) Configuring the Guest VLAN Function
Context
After the guest VLAN function is enabled, the device allows users to access resources in the Guest VLAN without 802.1X authentication. For example, the users can obtain the client software, upgrade the client, or run other upgrade programs.
Procedure
- Run system-view
The system view is displayed.
- Configure the guest VLAN function in the system or interface
view.
- In the system view:
- In the interface view:
By default, an interface is not added to the guest VLAN.
NOTE:
- The guest VLAN function can take effect only in 802.1X and MAC address authentication.
- When free IP subnets are configured, the guest VLAN function becomes invalid immediately.
- If the authentication function of the built-in Portal server is enabled, the guest VLAN cannot be configured on interfaces.
- The guest VLAN function takes effect only when a user sends untagged packets to the device.
- Different interfaces can be configured with different guest VLANs. After a guest VLAN is configured on an interface, the guest VLAN cannot be deleted.
- To make the VLAN authorization function take effect,
the link type and access control mode of the authentication interface
must meet the following requirements:
- When the link type is hybrid in untagged mode, the access control mode can be based on the MAC address or interface.
- When the link type is access or trunk, the access control mode can only be based on the interface.