How Do I Create A Guest VLAN Using The Web Interface On My ...

In this article, dot1x is enabled on all the ports so that all the hosts that are authorized are assigned to VLAN 1. On ports 1/0/1 and 1/0/24, guest VLAN is enabled. If guests connect to the port, they are assigned to VLAN 2000, so that guests cannot access the internal VLAN, but can access each other in the guest VLAN.

  1. Create VLAN 2000.
    1. Select Switching > VLAN > Basic > VLAN Configuration. A screen similar to the following displays. Image
    2. In the VLAN ID field, enter 2000.
    3. In the VLAN Type field, select Static.
    4. Click Add.
  2. Add ports to VLAN 2000.
    1. Select Switching > VLAN > Advanced > VLAN Membership. A screen similar to the following displays. Image
    2. In the VLAN ID list, select 2000 .
    3. Click Unit 1. The ports display.
    4. Click the gray boxes under ports 1 and 24 until U displays. The U specifies that the egress packet is untagged for the port.
    5. Click Apply.
  3. Set force authorized mode on ports 1/0/6 and 1/0/12.
    1. Select Security > Port Authentication > Advanced > Port Authentication. A screen similar to the following displays. Image
    2. Scroll down and select the Interface 1/0/6 and 1/0/12, check boxes.
    3. In the Control Mode list, select Force Authorized.
    4. Click Apply to save settings.
  4. Enable dot1x on the switch. Make sure that 1/0/12 and 1/0/6 are configured as force authorized before you do this step; otherwise you cannot access the switch through the Web Interface.
    1. Select Security > Port Authentication > Basic > 802.1x Configuration. A screen similar to the following displays. Image
    2. For Administrative Mode, select the Enable radio button.
    3. Click Apply to save settings.
  5. Configure the dot1x authentication list.
    1. Select Security > Management Security > Authentication List > Dot1x Authentication List. A screen similar to the following displays. Image
    2. Select the defaultList check box.
    3. In the 1 list, select RADIUS.
    4. Click Add.
  6. Configure the RADIUS authentication server.
    1. Select Security > Management Security > Radius > Server Configuration. A screen similar to the following displays. Image
    2. In the Radius Server IP Address field, enter 192.168.0.1.
    3. In the Secret Configured field, select Yes.
    4. In the Secret field, enter 12345.
    5. Click Add.
  7. Configure the guest VLAN.
    1. Select Security > Port Authentication > Advanced > Port Authentication. A screen similar to the following displays. Image
    2. Scroll down and select the port 1/0/1 and 1/0/24 check boxes.
    3. In the Guest VLAN ID field, enter 2000.
    4. Click Apply to save your settings.

For more information, see the following support articles:

  • What is the guest VLAN feature and how does it work with my managed switch?
  • How do I create a guest VLAN using CLI commands on my managed switch?

This article applies to the following managed switches and their respective firmware:

  • M5300 - firmware version 10.0.0.x
    • M5300-28G (GSM7228S)
    • M5300-5G (GSM7252S)
    • M5300-28G3 (GSM7328Sv2h2)
    • M5300-52G3 (GSM7352Sv2h2)
    • M5300-28G_POE+ (GSM7228PSv1h2)
    • M5300-52G-POE+ (GSM7252PSv1h2)
    • M5300-28GF3 (GSM7328FSv2)
  • M4100 - firmware version 10.0.1.x
    • M4100-26G (GSM7224v2h2)
    • M4100-50G (GSM7248v2h2)
    • M4100-26G-POE (GSM7226Pv1h1)
    • M4100-50G-POE+ (GSM7248Pv1h1)
    • M4100-26G-POE (FSM7226Pv1h1)
    • M4100-50-POE (FSM7250Pv1h1)
    • M4100-D12G (GSM5212v1h1)
    • M4100-D10-POE (FSM5210Pv1h1)
  • M7100 - firmware version 10.0.1.x
    • M7100-24X (XSM7224)
  • XSM7224S - firmware version 9.0.1.x
Last Updated:07/07/2025 | Article ID: 21804 Was this article helpful? Yes No

Tag » How To Set Vlan On Switch Guest Wifi