1-13[Switch-Ethernet1/0/1] mac-address security 0001-0002-0003 vlan 1# Configure the port to be silent for 30 seconds after intrusion protection is triggered.[Switch-Ethernet1/0/1] port-security intrusion-mode disableport-temporarily[Switch-Ethernet1/0/1] quit[Switch] port-security timer disableport 30Guest VLAN Configuration ExampleNetwork requirementsAs shown in Figure 1-2, Ethernet 1/0/2 connects to a PC and a printer, which are not used at the sametime. Configure the port to operate in macAddressOrUserLoginSecure mode and specify a guestVLAN for the port.z The PC must pass 802.1x authentication to connect to the network while the printer must passMAC address authentication to achieve network connectivity.z The switch’s port Ethernet 1/0/3 connects to the Internet. This port is assigned to VLAN 1. Normally,the port Ethernet 1/0/2 is also assigned to VLAN.z VLAN 10 is intended to be a guest VLAN. It contains an update server for users to download andupgrade their client software. When a user fails authentication, port Ethernet 1/0/2 is added toVLAN 10. Then the user can access only VLAN 10. The port goes back to VLAN 1 when the userpasses authentication.Figure 1-2 Network diagram for guest VLAN configurationInternetUpdate server Authentication serverPCVLAN 10Eth1/0/1Guest VLAN 10: VLAN 1Eth1/0/2 VLAN 1Eth1/0/3VLAN 2Eth1/0/4VLAN 10SwitchPrinterHubConfiguration procedureThe following configuration steps include configurations of AAA and RADIUS. For details about thesecommands, refer to AAA Command. The configurations on the 802.1x client and the RADIUS serverare omitted.