Allied Telesis AT-S63 User Manual

Page 737

Advertising
background image

AT-S63 Management Software Command Line User’s Guide

Section VIII: Port Security

737

A Guest VLAN is only supported when the operating
mode of the port is set to Single. The specified VLAN
must already exit on the switch.

vlanassignment

Specifies whether to use the VLAN assignments
entered in the user accounts on the RADIUS server.
Options are:

enabled

Specifies that the authenticator port is to

use the VLAN assignments returned by
the RADIUS server when a supplicant logs
on. This is the default setting.

disabled

Specifies that the authenticator port ignore

any VLAN assignment information
returned by the RADIUS server when a
supplicant logs on. The authenticator port
remains in its predefined VLAN
assignment even when the RADIUS
server returns a VLAN assignment when a
supplicant logs on.

securevlan

Controls the action of an authenticator port to
subsequent authentications after the initial
authentication where VLAN assignments have been
added to the user accounts on the RADIUS server. This
parameter only applies when the port is operating in the
Multiple operating mode. Options are:

on

Specifies that only those supplicants with

the same VLAN assignment as the initial
supplicant are authenticated. Supplicants
with a different or no VLAN assignment
are denied entry to the port. This is the
default setting.

off

Specifies that all supplicants, regardless of

their assigned VLANs, are authenticated.
However, the port remains in the VLAN
specified in the initial authentication,
regardless of the VLAN assignments of
subsequent authentications.

Description

This command sets ports to the authenticator role and configures the
authenticator role parameters. This command also removes port-based
access control from a port.

Advertising