224
C
HAPTER
17: 802.1
X
C
ONFIGURATION
c
CAUTION:
■
802.1x configurations take effect only after you enable 802.1x both globally
and for specified ports.
■
If you enable 802.1x for a port, you cannot set the maximum number of MAC
addresses that can be learnt for the port. Meanwhile, if you set the maximum
number of MAC addresses that can be learnt for a port, it is prohibited to
enable 802.1x for the port.
■
If you enable 802.1x for a port, it is not available to add the port to an
aggregation group. Meanwhile, if a port has been added to an aggregation
group, it is prohibited to enable 802.1x for the port.
■
Changing the access control method on a port by the
dot1x port-method
command will forcibly log out the online 802.1x users on the port.
■
When a device operates as an authentication server, its authentication method
for 802.1x users cannot be configured as EAP.
■
Handshaking packets need the support of the 3Com-proprietary client. They
are used to test whether or not a user is online.
■
As clients that are not of 3Com do not support the online user handshaking
function, switches cannot receive handshaking acknowledgement packets
Enable
802.1x for
specified
ports
In system
view
dot1x interface
interface-list
Required
By default, 802.1x is disabled on
all ports.
In port
view
interface
interface-type
interface-number
dot1x
quit
Set port access control
mode for specified
ports
dot1x port-control
{
authorized-force
|
unauthorized-force
|
auto
} [
interface
interface-list
]
Optional
By default, an 802.1x-enabled
port operates in the
auto
mode.
Set port access
method for specified
ports
dot1x port
-
method
{
macbased
|
portbased
} [
interface
interface-list
]
Optional
The default port access method is
MAC-address-based (that is, the
macbased
keyword is used by
default).
Set authentication
method for 802.1x
users
dot1x authentication-method
{
chap
|
pap
|
eap
}
Optional
By default, a switch performs
CHAP authentication in EAP
terminating mode.
Enable online user
handshaking
dot1x handshake enable
Optional
By default, online user
handshaking is enabled.
Enter Ethernet port
view
interface interface-type
interface-number
-
Enable the
handshaking packet
secure function
dot1x handshake secure
Optional
By default, the handshaking
secure function is disabled.
Table 162
Configure basic 802.1x functions
Operation
Command Remarks
Summary of Contents for Switch 4210 9-Port
Page 22: ...20 CHAPTER 1 CLI CONFIGURATION ...
Page 74: ...72 CHAPTER 3 CONFIGURATION FILE MANAGEMENT ...
Page 84: ...82 CHAPTER 5 VLAN CONFIGURATION ...
Page 96: ...94 CHAPTER 8 IP PERFORMANCE CONFIGURATION ...
Page 108: ...106 CHAPTER 9 PORT BASIC CONFIGURATION ...
Page 122: ...120 CHAPTER 11 PORT ISOLATION CONFIGURATION ...
Page 140: ...138 CHAPTER 13 MAC ADDRESS TABLE MANAGEMENT ...
Page 234: ...232 CHAPTER 17 802 1X CONFIGURATION ...
Page 246: ...244 CHAPTER 20 AAA OVERVIEW ...
Page 270: ...268 CHAPTER 21 AAA CONFIGURATION ...
Page 292: ...290 CHAPTER 26 DHCP BOOTP CLIENT CONFIGURATION ...
Page 318: ...316 CHAPTER 29 MIRRORING CONFIGURATION ...
Page 340: ...338 CHAPTER 30 CLUSTER ...
Page 362: ...360 CHAPTER 33 SNMP CONFIGURATION ...
Page 368: ...366 CHAPTER 34 RMON CONFIGURATION ...
Page 450: ...448 CHAPTER 39 TFTP CONFIGURATION ...
Page 451: ......
Page 452: ...450 CHAPTER 39 TFTP CONFIGURATION ...
Page 470: ...468 CHAPTER 40 INFORMATION CENTER ...
Page 496: ...494 CHAPTER 44 DEVICE MANAGEMENT ...