81• A super VLAN cannot be set as the guest VLAN. Similarly, a guest VLAN cannot be set as the superVLAN. For information about super VLAN, see VLAN in the Layer 2 – LAN Switching ConfigurationGuide.Configuration prerequisites• Create the VLAN to be specified as the guest VLAN.• To configure a port-based guest VLAN, make sure that the port access control method isportbased, and the 802.1X multicast trigger function is enabled.Configuration procedureFollow these steps to configure a guest VLAN:To do… Use the command… Remarks1. Enter system view system-view —2. Configure the guest VLAN forone or more portsIn system viewdot1x guest-vlan guest-vlan-id [ interface interface-list ] RequiredUse either approach.By default, a port isconfigured with noguest VLAN.In Ethernetinterface viewinterface interface-typeinterface-numberdot1x guest-vlan guest-vlan-idDifferent ports can be configured with different guest VLANs, but a port can be configured with only oneguest VLAN.Configuring an Auth-Fail VLAN• If the traffic from a user-side switch carries VLAN tags and the 802.1X authentication and Auth-Fail VLANfunctions are configured on the access port, you are recommended to configure different VLAN IDs forthe default VLAN of the port, and 802.1X Auth-Fail VLAN. This is to ensure the normal use of thefunctions.• A super VLAN cannot be set as the Auth-Fail VLAN. Similarly, an Auth-Fail VLAN cannot be set as thesuper VLAN. For information about super VLAN, see VLAN in the Layer 2 – LAN Switching ConfigurationGuide.Configuration prerequisites• Create the VLAN to be specified as the Auth-Fail VLAN.• To configure a port-based Auth-Fail VLAN, make sure that the port access control method isportbased, and the 802.1X multicast trigger function is enabled.