33-8
To do…
Use the command…
Remarks
Enter system view
—
system-view
Create an ISP domain and
enter its view
—
domain
isp-name
Optional
Set the VLAN assignment
mode
vlan-assignment-mode
{
integer
|
string
| vlan-list
}
By default, the VLAN assignment
mode is integer.
Create a VLAN and enter its
view
—
vlan
vlan-id
This operation is required if the
VLAN assignment mode is set to
string.
Set a VLAN name for VLAN
assignment
name
string
z
In string mode, if the VLAN ID assigned by the RADIUS server is a character string containing only
digits (for example, 1024), the switch first regards it as an integer VLAN ID: the switch transforms
the string to an integer value and judges if the value is in the valid VLAN ID range; if it is, the switch
assigns the authenticated port to the VLAN with the integer value as the VLAN ID (VLAN 1024, for
example).
z
To implement dynamic VLAN assignment on a port where both MSTP and 802.1x are enabled, you
must set the MSTP port to an edge port.
z
Only 802.1X authentication and RADIUS server authentication-based MAC address authentication
support the Auto VLAN feature.
z
After a VLAN list is issued to a port, if you use commands to assign/remove the port to/from a VLAN
in the VLAN list, some users will be disconnected.
z
After a VLAN list is issued to a port, you can use commands to change the default VLAN of the port.
However, the change takes effect after all the users are disconnected from the port.
Configuring the Attributes of a Local User
When
local
scheme is chosen as the AAA scheme, you should create local users on the switch and
configure the relevant attributes.
The local users are users set on the switch, with each user uniquely identified by a username. To make
a user who is requesting network service pass local authentication, you should add an entry in the local
user database on the switch for the user.
Follow these steps to configure the attributes of a local user:
To do…
Use the command…
Remarks
Enter system view
—
system-view