Allied Telesis AT-S63 User Manual
Page 623

AT-S63 Management Software Command Line Interface User’s Guide
Section VIII: Port Security
623
A Guest VLAN is only supported when the operating 
mode of the port is set to Single. The specified VLAN 
must already exit on the switch.
vlanassignment
Specifies whether to use the VLAN assignments 
entered in the user accounts on the RADIUS server. 
Options are:
enabled
Specifies that the authenticator port is to
use the VLAN assignments returned by 
the RADIUS server when a supplicant logs 
on. This is the default setting.
disabled
Specifies that the authenticator port ignore
any VLAN assignment information 
returned by the RADIUS server when a 
supplicant logs on. The authenticator port 
remains in its predefined VLAN 
assignment even when the RADIUS 
server returns a VLAN assignment when a 
supplicant logs on.
securevlan
Controls the action of an authenticator port to 
subsequent authentications after the initial 
authentication where VLAN assignments have been 
added to the user accounts on the RADIUS server. This 
parameter only applies when the port is operating in the 
Multiple operating mode. Options are:
on
Specifies that only those supplicants with
the same VLAN assignment as the initial 
supplicant are authenticated. Supplicants 
with a different or no VLAN assignment 
are denied entry to the port. This is the 
default setting.
off
Specifies that all supplicants, regardless of
their assigned VLANs, are authenticated. 
However, the port remains in the VLAN 
specified in the initial authentication, 
regardless of the VLAN assignments of 
subsequent authentications.
Description
This command sets ports to the authenticator role and configures the 
authenticator role parameters. This command also removes port-based 
access control from a port.
