![D-Link DES-3528 - xStack Switch - Stackable Cli Reference Manual Download Page 515](http://html.mh-extra.com/html/d-link/des-3528-xstack-switch-stackable/des-3528-xstack-switch-stackable_cli-reference-manual_76439515.webp)
xStack® DES-3528/DES-3552 Series Layer 2 Managed Stackable Fast Ethernet Switch CLI Reference Guide
515
config authentication ports
Purpose
This command is used to configure security port(s).
Syntax
config authentication ports [<portlist> | all] {auth_mode [port_based | host_based
{vlanid <vidlist> state [enable | disable]}] | multi_authen_methods [none | any |
dot1x_impb | impb_jwac | impb_wac | mac_impb]}(1)
Description
This command is used to configure security port(s).
Parameters
ports
- Specifies port(s) to be configured.
<
portlist
> - Enter the list of ports to be configured here.
all
- Specifies all ports on the Switch.
auth_mode
- (Optional) Specifies the authentication mode used.
port_based
- If one of the attached hosts passes the authentication, all hosts on the same
port will be granted to access network. If the user fails to authorize, this port will keep trying
the next authentication
host_based
- Every user can be authenticated individually. v2.01 and later, can authenticate
client on specific authentication VLAN(s).
vlanid
- (Optional) Specific authentication VLAN(s). This is useful when different VLANs on
the Switch have different authentication requirements. For example, traffic from wireless APs
on VLAN1 do not require authentication, while ordinary wired traffic on VLAN2 requires
authentication.
<
vidlist
> - Enter the VLAN ID list here.
state
- (Optional) Specifies the VID list's authentication state.
enable
- Assign the specified VID list as authentication VLAN(s).
disable
- Remove the specified VID list from authentication VLAN(s). If "vlanid" is not
specified, or all VLANs is disabled, means do not care which VLAN the client comes from, the
client will be authenticated if the client's MAC(not care the VLAN) is not authenticated. After
the client is authenticated, the client will not be re-authenticated when received from other
VLANs. All VLANs are disabled by default.
Note:
When port’s authorization mode is changed to port-based, previously authentication
VLAN(s) on this port will be clear.
multi_authen_methods
- (Optional) Specifies the method for compound authentication.
none - Compound authentication is not enabled,
any
- If any one of the authentication method (802.1X, MAC-AC, WAC and JWAC) passes,
then pass.
dot1x_impb
- Dot1x will be verified first, and then IMPB will be verified. Both authentication
methods need to be passed.
impb_jwac
- JWAC will be verified first, and then IMPB will be verified. Both authentication
methods need to be passed.
impb_wac
- WAC will be verified first, and then IMPB will be verified. Both authentication
methods need to be passed.
mac_impb
- MAC-AC will be verified first, and then IMPB will be verified. Both authentication
methods need to be passed.
Restrictions
Only Administrator and Operator-level users can issue this command.
Example usage:
The following example sets the compound authentication method of all ports to any:
DES-3528:admin# config authentication ports all multi_authen_methods any
Command: config authentication ports all multi_authen_methods any
Success.
DES-3528:admin#
Summary of Contents for DES-3528 - xStack Switch - Stackable
Page 1: ......