426
C
HAPTER
21: 802.1
X
C
ONFIGURATION
By default, the keys of RADIUS authentication/authorization and accounting packets
are all “3com”.
Tag VLAN Assignment
on Trunk/Hybrid Port
Supported by 802.1x
Authentication
Currently, the 802.1x authentication module supports Tag VLAN assignment only on
Access port. But some applications (for example, this kind of connection: switch—IP
phone—PC) needs 802.1x authentication on Trunk/Hybrid port. For this reason, a
new feature, Tag VLAN assignment on Trunk/Hybrid port, is designed.
■
After a MAC address authentication succeeds, the address information is
synchronously assigned in the whole fabric.
■
When a user logs off, the system restores the original VLAN information on the
Trunk/Hybrid port and synchronously deletes the corresponding address
information from the whole fabric.
Identifier Authentication
Method Attribute in
RADIUS
The purpose of adding identifier authentication method attribute into RADIUS
authentication packets is to distinguish different access modes, such as Portal,
802.1x, and PPPoE. For the non-3Com client block function, you can limit its
operation range to only 802.1x authentication, that is, allow the function to take
effect only when the identifier authentication method attribute is 802.1x.
The adding of identifier authentication method attribute into an RADIUS
authentication packet is to fill the Framed Protocol attribute in the RADIUS
authentication request packet based on the access mode of the user.
Setting Retransmission
Times of RADIUS
Request Packet
Since RADIUS protocol uses UDP packets to carry the data, the communication
process is not reliable. If the RADIUS server has not responded to NAS before timeout,
NAS has to retransmit the RADIUS request packet. If it transmits more than the
specified
retry-times
, NAS considers the communication with the primary and
secondary RADIUS servers has been disconnected.
You can use the following command to set the retransmission times of the RADIUS
request packet.
Perform the following configurations in RADIUS Scheme View.
Table 459
Setting Retransmission Times of RADIUS Request Packet
By default, RADIUS request packet will be retransmitted up to three times.
Setting the Supported
Type of the RADIUS
Server
The Switch 5500 supports the standard RADIUS protocol and the extended RADIUS
service platforms.
You can use the following command to set the supported types of RADIUS servers.
Perform the following configurations in RADIUS Scheme View.
Table 460
Setting the Supported Type of the RADIUS Server
Operation
Command
Set retransmission times of RADIUS request packet
retry
retry_times
Restore the default value of retransmission times
undo retry
Operation
Command
Setting the Supported Type of RADIUS Server
server-type { 3com | standard
}
Restore the RADIUS server type to the default setting
undo server_type
Summary of Contents for 5500 SI - Switch - Stackable
Page 24: ...24 ABOUT THIS GUIDE...
Page 50: ...50 CHAPTER 1 GETTING STARTED...
Page 54: ...54 CHAPTER 2 ADDRESS MANAGEMENT CONFIGURATION...
Page 78: ...78 CHAPTER 3 PORT OPERATION...
Page 88: ...88 CHAPTER 4 XRN CONFIGURATION...
Page 122: ...122 CHAPTER 8 VLAN VPN CONFIGURATION...
Page 216: ...216 CHAPTER 15 SSH TERMINAL SERVICES...
Page 268: ...268 CHAPTER 16 IP ROUTING PROTOCOL OPERATION...
Page 308: ...308 CHAPTER 17 NETWORK PROTOCOL OPERATION...
Page 349: ...349...
Page 350: ...350 CHAPTER 18 MULTICAST PROTOCOL...
Page 522: ...522 CHAPTER 22 FILE SYSTEM MANAGEMENT...
Page 584: ...584 CHAPTER 30 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Page 600: ...600 CHAPTER 31 MSDP CONFIGURATION...
Page 614: ...614 CHAPTER 32 CLUSTERING...
Page 670: ...670 CHAPTER C AUTHENTICATING THE SWITCH 5500 WITH CISCO SECURE ACS...