728 CHAPTER 50: 802.1X CONFIGURATION
n
■ You can neither add an 802.1x-enabled port into an aggregation group nor 
enable 802.1x on a port being a member of an aggregation group.
■ Once enabled with the 802.1x multicast trigger function, a port sends 
multicast trigger messages to the client periodically to initiate authentication.
■ For a user-side device sending untagged traffic, the voice VLAN function and 
8021.x are mutually exclusive and cannot be configured together on the same 
port. For details about voice VLAN, refer to “Voice VLAN Configuration” on 
page 99.
■ In EAP relay authentication mode, the authenticator encapsulates the 802.1x 
user information in the EAP attributes of RADIUS packets and sends the 
packets to the RADIUS server for authentication. In this case, you can configure 
the user-name-format command but it does not take effect. For information 
about the user-name-format command, refer to “Configuring RADIUS” on 
page 765.
■ If the username of a supplicant contains the version number or one or more 
blank spaces, you can neither retrieve information nor disconnect the 
supplicant by using the username. However, you can use items such as IP 
address and connection index number to do so.
Configuring a Guest 
VLAN
Configuration
Prerequisites
■ Enable 802.1x
■ Set the port access control method to portbased for the port
■ Set the port access control mode to auto for the port
■ Create the VLAN to be specified as the guest VLAN
Configuration Procedure Follow these steps to configure Guest VLAN:
Set the port access control 
method for the port 
dot1x port-method 
{ macbased | portbased } 
Optional
macbased by default 
Set the maximum number of 
users for the port 
dot1x max-user 
user-number 
Optional
By default, the maximum 
number of concurrent users 
accessing a port is 256. 
Enable online user handshake  dot1x handshake Optional
Enabled by default 
Enable multicast trigger  dot1x multicast-trigger Optional
Enabled by default
To do…  Use the command…  Remarks 
To do…  Use the command…  Remarks 
Enter system view  system-view -