94• If the 802.1X-enabled port performs MAC-based access control, perform the followingoperations for the port:{ Configure the port as a hybrid port.{ Enable MAC-based VLAN on the port. For more information about MAC-based VLANs, seeLayer 2—LAN Switching Configuration Guide.{ Assign the port to the 802.1X guest VLAN as an untagged member.Configuration procedureTo configure an 802.1X guest VLAN:Step Command Remarks1. Enter system view. system-view N/A2. Enter Layer 2 Ethernetinterface view.interface interface-typeinterface-number N/A3. Configure the 802.1X guestVLAN on the port. dot1x guest-vlan guest-vlan-id By default, no 802.1X guest VLANis configured on any port.Configuring an 802.1X Auth-Fail VLANConfiguration guidelinesWhen you configure an 802.1X Auth-Fail VLAN, follow these restrictions and guidelines:• Assign different IDs to the voice VLAN, the port VLAN, and the 802.1X Auth-Fail VLAN on a port.The assignment makes sure the port can correctly process VLAN-tagged incoming traffic.• You can configure only one 802.1X Auth-Fail VLAN on a port. The 802.1X Auth-Fail VLANs ondifferent ports can be different.• When you configure multiple security features on a port, follow the guidelines in Table 8.Table 8 Relationships of the 802.1X Auth-Fail VLAN with other featuresFeature Relationship description ReferenceSuper VLANYou cannot specify a VLAN asboth a super VLAN and an802.1X Auth-Fail VLAN.See Layer 2—LAN SwitchingConfiguration Guide.MAC authentication guestVLAN on a port that performsMAC-based access controlThe 802.1X Auth-Fail VLAN hasa high priority.See "Configuring MACauthentication."Port intrusion protection actionson a port that performsMAC-based access controlThe 802.1X Auth-Fail VLANfeature has higher priority thanthe block MAC action.The 802.1X Auth-Fail VLANfeature has lower priority thanthe shutdown port action of theport intrusion protection feature.See "Configuring port security."Configuration prerequisitesBefore you configure an 802.1X Auth-Fail VLAN, complete the following tasks: