802.1X wired: fix the RADIUS reach, policy and interface mode
SW1 is set up to require 802.1X on Fa0/1, with the RADIUS server RADIUS-SRV at 10.0.99.10 (shared key RadKey99). On fail or timeout a client should land in VLAN 99 (guest). The AAA model is not enabled, dot1x system auth control is off, the port is still in force-authorized mode, and the guest VLAN is not set. Fix all five issues so a successful auth lands in VLAN 10 and a failure lands in VLAN 99.
SW1 Fa0/1 -> PC1 (supplicant, VLAN 10 if authorized, VLAN 99 guest if not) SW1 Gi0/23 -> RADIUS-SRV (10.0.99.10, key RadKey99, user alice / Alice2026) VLAN 10 = USERS, VLAN 99 = GUEST
Topology
Stuck on a lab, or not sure what to practice next?
Talk it through with a mentor on a free 20-minute call. We look at your lab, your exam date and your weak spots, and you leave with a plan.