After a port is added to a Guest VLAN, the switch will re-authenticate the first access user of this port
(namely, the
whose unicast M
by the switch) p
user
passes the re-a
cation, this port
and thus the user
ccess the
n
first user
uthenti
AC address is learned
will exit the Guest VLAN,
eriodically. If this
can a
etwork normally.
z
Guest VLANs are implemented in the mode of adding a port to a VLAN. For example, when
nnected to a port, if the first user fails in the a
ntication, the other users can
access only the contents of the Guest VLAN. The switch will re-authenticate only the first user
o
ticat
than one
ort, y
VLAN
z
nected to an existing port failed to pass a
e
port to the Guest VLAN. Therefore, the Guest VLAN can separate unauthenticated users on an
access port. When it comes to a trunk port or a hybrid port, if a packet itself has a VLAN tag and be
in the VLAN that the port allows to pass, the packet will be forwarded perfectly without the influence
of the Guest VLAN. That is, packets can be forwarded to the VLANs other than the Guest VLAN
through the trunk port and the hybrid port, even users fail to pass authentication.
multiple users are co
uthe
accessing this port, and the
client is connected to a p
After users that are con
ther users cannot be authen
ou cannot configure a Guest
ed again. Thus, if more
for this port.
uthentication, the switch adds th
ow these steps to configure a Guest VLAN:
Foll
To do...
Use the command...
Remarks
Enter system view
system-view
—
E ter Ethernet port view
interface interface-type
interface-number
—
n
Co
the
lan-id
configured for a port by default.
nfigure the Guest VLAN for
current port
mac-authentication
guest-vlan v
Required
By default, no Guest VLAN is
turn to system view
quit
—
Re
Configure the interval at which
the switch re-authenticates
users in Guest VLANs
mac-authentication timer
guest-vlan-reauth interval
Optional
By default, the switch
re-authenticates the users in
Guest VLANs at the interval of
30 seconds by default.
35-5