Guest I-SID

Guest I-SID support provides limited network access until the client is authenticated. The switches uses the Guest I-SID to forward traffic until the client authenticates and receives other VLAN:ISID bindings from the RADIUS server.

Guest I-SID is a per-port option. You must configure an I-SID either as a C-VLAN or as an ELAN with an associated platform VLAN before you can configure it as the Guest I-SID. After you configure the Guest I-SID and you enable EAP, an untagged S-UNI is created based on the supplied I-SID. When you change the Guest I-SID while EAP is enabled, the untagged S-UNI is replaced on the port.

In MHSA mode, only one untagged S-UNI can exist on a port at one time. Consider the following:

In MHMV mode, the untagged S-UNIs provided by the RADIUS server are treated as MAC-based untagged S-UNIs, which are different from the untagged S-UNI on the port. Consider the following factors: