Configuring an 802.1X critical VLAN

Typically, when a client user is assigned to the 802.1X critical VLAN on a port, the device sends an EAP-Failure packet to the client. Some 802.1X clients, such as Windows built-in 802.1X clients, cannot respond to the EAP-Request/Identity packets of the device if they have received an EAP-Failure packet. As a result, reauthentication fails for these clients when an authentication server is reachable.

To solve this problem, configure the device to send EAP-Success packets instead of EAP-Failure packets for 802.1X user assignment to the 802.1X critical VLAN. This configuration ensures that all 802.1X clients can perform reauthentication.