auth-default-vlan

Specifies the auth-default VLAN globally.
Syntax
auth-default-vlan vlan-id
no auth-default-vlan vlan-id
Command Default

The auth-default VLAN is not specified.

Parameters
vlan-id
Specifies the VLAN ID of the auth-default VLAN.
Modes

Authentication configuration mode

Usage Guidelines

The auth-default VLAN must be configured to enable authentication.

A VLAN must be configured as auth-default VLAN to enable authentication. When any port is enabled for 802.1X authentication or MAC authentication, the client is moved to this VLAN by default.

The auth-default VLAN is also used in the following scenarios:

  • When the RADIUS server does not return VLAN information upon authentication, the client is authenticated and remains in the auth-default VLAN.
  • If RADIUS timeout happens during the first authentication attempt and the timeout action is configured as "Success", the client is authenticated in the auth-default VLAN. If the RADIUS server is not available during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN.

The no form of the command disables the auth-default VLAN.

Examples

The following example creates an auth-default VLAN with VLAN 2.

device(config)# authentication
device(config-authen)# auth-default-vlan 2
History
Release version Command history
08.0.20 This command was introduced.