Non-authenticated terminals can access a virtual network by using statically configured VLANs. Such terminals may include printers, cameras, sensors, industrial devices, and other dumb terminals that cannot perform 802.1X, Portal, or comparable interactive authentication. Their access interfaces and service VLANs are therefore configured in advance and mapped to the required VN.
Dynamic VLAN authorization requires a completed authentication or identification process. Normally, an authentication server returns a VLAN or other authorization attribute after validating the user or terminal. Because the question specifically refers to non-authenticated terminals, dynamically authorizing a VLAN is not the applicable mechanism. The wired-mode and wireless-mode authorization options are likewise associated with authentication-based policy delivery rather than unconditional VN access.
Huawei’s VN design guidance states that LAN-side physical interfaces and VLANs are assigned to the appropriate departments or services and then associated with corresponding VRFs or VNs. It also explains that a department may use an independent physical interface or share an interface while maintaining isolation through VLANs. Therefore, configuring a static VLAN is the correct method.
==================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit