critical-vlan

Specifies the VLAN into which the client should be placed when the RADIUS server times out while authenticating or re-authenticating users.
Syntax
critical-vlan vlan-id
no critical-vlan vlan-id
Command Default

The client is not part of the critical VLAN.

Parameters
vlan-id
Specifies the VLAN ID of the specific critical VLAN.
Modes

Authentication configuration mode

Usage Guidelines

When critical VLAN is configured and the authentication time out action is specified as critical VLAN under the port using the authentication timeout-action critical-vlan command at the interface level and if RADIUS timeout happens, the client is moved to the critical VLAN and any access policies applied to the critical VLAN is applied to the client.

The VLAN which is configured as a critical VLAN must be a valid VLAN configured on the device.

The no form of the command disables the critical VLAN by removing the client from the VLAN.

Examples

The following example configures VLAN 20 as critical VLAN.

device(config)# authentication
device(config-authen)# critical-vlan 20
History
Release version Command history
08.0.20 This command was introduced.