Guest vlan, Guest vlan 5 – Allied Telesis AT-8100 Series User Manual
Page 1075
AT-8100 Switch Command Line User’s Guide
1075
Guest VLAN
An authenticator port in the unauthorized state typically accepts and
transmits only 802.1x packets while waiting to authenticate a supplicant.
However, you can configure an authenticator port to be a member of a
guest VLAN when no supplicant is logged on or when a supplicant has
failed authentication. Any supplicant using the port is not required to log on
and has full access to the resources of the guest VLAN.
If the switch receives 802.1x packets on the port, signalling that a
supplicant is logging on, the authentication process continues normally. If
dynamic VLAN creation is enabled using AUTH DYNAMIC-VLAN-
CREATION SINGLE, the authenticator port will be moved to the VLAN
assigned by the RADIUS Server. If dynamic VLAN creation is disabled
using NO AUTH DYNAMIC-VLAN-CREATION, after successful
authentication, the port will be moved to Default VLAN 1, or the configured
native VLAN (if a VLAN is configured). When the supplicant logs off, the
port automatically returns to the guest VLAN.
Note
The Guest VLAN feature is only supported on an authenticator port
in the Single-host operating mode.