authentication auth-default-vlan

Specifies the authentication default VLAN at the interface level.
Syntax
authentication auth-default-vlan vlan-id
no authentication auth-default-vlan vlan-id
Command Default

The auth-default VLAN is not specified.

Parameters
vlan-id
Specifies the VLAN ID of the auth-default VLAN.
Modes

Interface configuration mode

Usage Guidelines

The auth-default VLAN specified at the interface level overrides the auth-default VLAN configured using the auth-default-vlan command at the global level. The configured auth-default VLAN configured at the global level will still be applicable to other ports that don't have auth-default VLAN configured at the interface level.

The local auth-default VLAN must be configured to enable authentication.

A VLAN must be configured as auth-default VLAN to enable authentication. When any port is enabled for 802.1X authentication or MAC authentication, the client is moved to this VLAN by default.

The auth-default VLAN is also used in the following scenarios:

  • When the RADIUS server does not return VLAN information upon authentication, the client is authenticated and remains in the auth-default VLAN.
  • If RADIUS timeout happens during the first authentication attempt and the timeout action is configured as "Success", the client is authenticated in the auth-default VLAN. If the RADIUS server is not available during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN.

The no form of the command disables the auth-default VLAN.

Examples

The following example creates a default VLAN with VLAN 3.

device(config)# authentication
device(config-authen)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# authentication auth-default-vlan 3
History
Release version Command history
08.0.20 This command was introduced.