C
HAPTER
25
| General Security Measures
Network Access (MAC Address Authentication)
– 659 –
network-access
guest-vlan
Use this command to assign all traffic on a port to a guest VLAN when
802.1x authentication is rejected. Use the no form of this command to
disable guest VLAN assignment.
SYNTAX
network-access guest-vlan vlan-id
no network-access guest-vlan
vlan-id - VLAN ID (Range: 1-4093)
DEFAULT SETTING
Disabled
COMMAND MODE
Interface Configuration
COMMAND USAGE
◆ The VLAN to be used as the guest VLAN must be defined and set as
active (See the vlan database command).
◆ When used with 802.1X authentication, the intrusion-action must be
set for “guest-vlan” to be effective (see the dot1x intrusion-action
command).
EXAMPLE
Console(config)#interface ethernet 1/1
Console(config-if)#network-access guest-vlan 25
Console(config-if)#
network-access
link-detection
Use this command to enable link detection for the selected port. Use the
no form of this command to restore the default.
SYNTAX
[no] network-access link-detection
DEFAULT SETTING
Disabled
COMMAND MODE
Interface Configuration
EXAMPLE
Console(config)#interface ethernet 1/1
Console(config-if)#network-access link-detection
Console(config-if)#