Operation Manual – 802.1x and System Guard
H3C S3100-52P Ethernet switch
Chapter 1 802.1x Configuration
1-20
Note:
z
As for the
dot1x max-user
command, if you execute it in system view without
specifying the
interface-list
argument, the command applies to all ports. You can
also use this command in port view. In this case, this command applies to the
current port only and the
interface-list
argument is not needed.
z
As for the configuration of 802.1x timers, the default values are recommended.
1.4 Advanced 802.1x Configuration
Advanced 802.1x configurations, as listed below, are all optional.
z
Configuration concerning CAMS, including multiple network adapters detecting,
proxy detecting, and so on.
z
Client version checking configuration
z
DHCP–triggered authentication
z
Guest VLAN configuration
z
802.1x re-authentication configuration
z
Configuration of the 802.1x re-authentication timer
You need to configure basic 802.1x functions before configuring the above 802.1x
features.
1.4.1 Configuring Proxy Checking
Follow these steps to configure proxy checking:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Enable proxy checking
function globally
dot1x
supp-proxy-check
{
logoff
|
trap
}
Required
By default, the 802.1x
proxy checking function is
globally disabled.
In system
view
dot1x
supp-proxy-check
{
logoff
|
trap
}
[
interface
interface-list
]
interface
interface-type
interface-number
Enable proxy
checking for a
port/specified
ports
In port
view
dot1x
supp-proxy-check
{
logoff
|
trap
}
Required
By default, the 802.1x
proxy checking is disabled
on a port.