C613-50631-01 Rev A Command Reference for IE340 Series 2257
AlliedWare Plus™ Operating System - Version 5.5.3-0.x
AUTHENTICATION COMMANDS
AUTH
VLAN-RESTRICTION
auth vlan-restriction
Overview Use this command to restrict port authenticated supplicants on an interface to one
per VLAN. This is useful, for example, if you have configured multiple supplicants
on an interface but you want to restrict network access to a single IP phone and a
single authorized workstation.
Use the no variant of this command to remove the single supplicant per VLAN
restriction.
Syntax
auth vlan-restriction
no auth vlan-restriction
Default Not configured
Mode Interface Configuration for a static channel, a dynamic (LACP) channel group, or a
switch port; or Authentication Profile mode.
Usage notes This is a port authentication command, so you should first configure 802.1X, MAC,
or web authentication. In addition, configure multi-supplicants on the interface
using the auth host-mode multi-supplicant command.
This command works with both dynamic VLANs and static voice VLAN
configurations.
Examples To restrict supplicants to a one per VLAN on interface port1.0.2, use the following
commands:
awplus# configure terminal
awplus(config)# interface port1.0.2
awplus(config-if)# auth vlan-restriction
To remove the one per VLAN supplicant restriction on interface port1.0.2, use the
following commands:
awplus# configure terminal
awplus(config)# interface port1.0.2
awplus(config-if)# no auth vlan-restriction
Related
commands
auth dynamic-vlan-creation
auth host-mode
auth-mac enable
auth-web enable
dot1x port-control
show auth interface
show dot1x interface
switchport voice vlan