1-13
Configuring Basic 802.1x Functions
Table 1-1
Configure basic 802.1x functions
Operation
Command
Remarks
Enter system view
system-view
—
Enable 802.1x globally
dot1x
Required
By default, 802.1x is disabled
globally.
In system
view
dot1x
interface
interface-list
interface
interface-type
interface-number
dot1x
Enable
802.1x for
specified
ports
In port
view
quit
Required
By default, 802.1x is disabled on all
ports.
In system
view
dot1x
port-control
{
authorized-force
|
unauthorized-force
|
auto
}
[
interface interface-list
]
interface
interface-type
interface-number
dot1x
port-control
{
authorized-force
|
unauthorized-force
|
auto
}
Set port
access
control
mode for
specified
ports
In port
view
quit
Optional
By default, an 802.1x-enabled port
operates in the
auto
mode.
In system
view
dot1x
port
-
method
{
macbased
|
portbased
} [
interface
interface-list
]
interface
interface-type
interface-number
dot1x
port
-
method
{
macbased
|
portbased
}
Set port
access
method
for
specified
ports
In port
view
quit
Optional
The default port access method is
MAC-address-based (that is, the
macbased
keyword is used by
default).
Set authentication
method for 802.1x
users
dot1x
authentication-method
{
chap
|
pap
|
eap
}
Optional
By default, a switch performs CHAP
authentication in EAP terminating
mode.
Enable online user
handshaking
dot1x handshake enable
Optional
By default, online user handshaking
is enabled.
Enter Ethernet port
view
interface interface-type
interface-number
—
Enable the
handshaking packet
secure function
dot1x handshake secure
Optional
By default, the handshaking secure
function is disabled.