authentication auth-vlan-mode

Enables multiple-untagged mode on a specific Flexible authentication-enabled port and allows it to be member of multiple untagged VLANs.
Syntax
authentication auth-vlan-mode { multiple-untagged }
no authentication auth-vlan-mode { multiple-untagged }
Command Default

Flexible authentication-enabled port can be member of only one untagged VLAN.

Parameters
multiple-untagged
Allows the client to be assigned to multiple untagged VLANs on authentication.
Modes

Interface configuration mode

Usage Guidelines

Reload is not required to change the VLAN mode. However, existing sessions will be cleared if the command is applied to an individual interface.

The VLAN mode specified at the interface level overrides the VLAN mode configured using the auth-vlan-mode command at the global level. The configured VLAN mode configured at the global level will still be applicable to other ports that don't have the VLAN mode configured at the interface level.

Single untagged mode is only applicable to untagged VLANs returned by RADIUS.

The no form of the command returns the VLAN mode to single untagged. Port can be assigned to only one untagged VLAN on authentication.

Examples

The following example configures multiple untagged VLAN mode on interface 1/1/1.

device# configure terminal
device(config)# interface ethernet 1/1/1
(config-if-e1000-1/1/1)# authentication auth-vlan-mode multiple-untagged

The following example clears all sessions on a Flexible authentication enabled interface and restores the single untagged VLAN mode.

device# configure terminal
device(config)# interface ethernet 1/1/1
(config-if-e1000-1/1/1)# no authentication auth-vlan-mode multiple-untagged
History
Release version Command history
08.0.30b This command was introduced.