- Assign the IP address for the Web Management Interface.
- Select System > Management > Network Interface > IPv4 Network Configuration.
A screen similar to the following displays.

- For Current Network Configuration Protocol, select the None radio button.
- In the IP Address field, enter 192.168.0.5.
- In the Subnet Mask field, enter 255.255.255.0.
- Click Apply.
- Select System > Management > Network Interface > IPv4 Network Configuration.
- Create VLAN 2000.
- Select Switching > VLAN > Basic > VLAN Configuration.
A screen similar to the following displays.

- In the VLAN ID field, enter 2000.
- In the VLAN Type field, select Static.
- Click Add.
- Select Switching > VLAN > Basic > VLAN Configuration.
- Set force authorized mode on ports 1/0/6 and 1/0/12.
- Select Security > Port Authentication > Advanced > Port Authentication.
A screen similar to the following displays.

- Under Port Authentication, scroll down and select the 1/0/6 and 1/0/12 check boxes.
- In the Control Mode list, select Force Authorized.
- Click Apply to save settings.
- Select Security > Port Authentication > Advanced > Port Authentication.
- Enable dot1x on the switch.
Make sure that 1/0/12 and 1/0/6 are configured as force authorized before you do this step; otherwise, you cannot access the switch through the Web Management Interface.
- Select Security > Port Authentication > Basic > 802.1x Configuration.
A screen similar to the following displays.

- For Administrative Mode, select the Enable radio button.
- For VLAN Assignment Mode, select the Enable radio button.
- Click Apply to save settings.
- Select Security > Port Authentication > Basic > 802.1x Configuration.
- Configure the dot1x authentication list.
- Select Security > Management Security > Authentication List > Dot1x Authentication List.
A screen similar to the following displays.

- Select the defaultList check box.
- In the 1 list, select RADIUS.
- Click Add.
- Select Security > Management Security > Authentication List > Dot1x Authentication List.
- Configure the RADIUS authentication server.
- Select Security > Management Security > Radius > Server Configuration.
A screen similar to the following displays.

- In the Radius Server IP Address field, enter 192.168.0.1.
- In the Secret Configured field, select Yes.
- In the Secret field, enter 12345.
- Click Add.
- Select Security > Management Security > Radius > Server Configuration.
For more information, see the following support articles:
- What is VLAN assignment using RADIUS and how does it work with my managed switch?
- How do I assign VLANs using RADIUS on my managed switch using CLI commands?
This article applies to the following managed switches and their respective firmware:
- M5300 - firmware version 10.0.0.x
-
- M5300-28G (GSM7228S)
- M5300-5G (GSM7252S)
- M5300-28G3 (GSM7328Sv2h2)
- M5300-52G3 (GSM7352Sv2h2)
- M5300-28G_POE+ (GSM7228PSv1h2)
- M5300-52G-POE+ (GSM7252PSv1h2)
- M5300-28GF3 (GSM7328FSv2)
- M4100 - firmware version 10.0.1.x
-
- M4100-26G (GSM7224v2h2)
- M4100-50G (GSM7248v2h2)
- M4100-26G-POE (GSM7226Pv1h1)
- M4100-50G-POE+ (GSM7248Pv1h1)
- M4100-26G-POE (FSM7226Pv1h1)
- M4100-50-POE (FSM7250Pv1h1)
- M4100-D12G (GSM5212v1h1)
- M4100-D10-POE (FSM5210Pv1h1)
- M7100 - firmware version 10.0.1.x
-
- M7100-24X (XSM7224)
- XSM7224S - firmware version 9.0.1.x