Operation Manual – 802.1x-HABP-MAC Authentication
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 802.1x Configuration
1-18
Note:
z
You can specify a tagged VLAN as the guest VLAN for a Hybrid port, but the guest
VLAN does not take effect. Similarly, if a guest VLAN for a Hybrid port is in operation,
you cannot configure the guest VLAN to carry tags.
z
Configurations in system view are effective to all ports while configurations in
interface view are effective to the current port only.
z
If a port’s access control method is
portbased
, its guest VLAN can take effect; if a
port’s access control method is
macbased
, its guest VLAN can be configured but
cannot take effect.
z
A port can be configured with only one guest VLAN. But different ports can have
different guest VLANs.
Caution:
If the data flows from a user-side device include VLAN tags, and 802.1x and guest
VLAN are enabled on the access port, you are recommended to configure different
VLAN IDs for the Voice VLAN, the default port VLAN, and the guest VLAN of 802.1x.
1.4 Displaying and Maintaining 802.1x
To do…
Use the command…
Remarks
Display 802.1x session
information, statistics, or
configuration information
of specified or all ports
display dot1x
[
sessions
|
statistics
] [
interface
interface-list
]
Available in any view
Clear 802.1x statistics
reset dot1x statistics
[
interface interface-list
]
Available in user view
1.5 802.1x Configuration Example
I. Network requirements
z
The access control method of
macbased
is required on the port to control
supplicants.
z
All supplicants belong to default domain aabbcc.net, which can accommodate up
to 30 users. RADIUS authentication is performed at first, and then local
authentication when no response from the RADIUS server is received. If the
RADIUS accounting fails, the authenticator gets users offline.