![H3C S9500E Series Security Configuration Manual Download Page 76](http://html1.mh-extra.com/html/h3c/s9500e-series/s9500e-series_security-configuration-manual_3156952076.webp)
76
•
For remote RADIUS authentication, the username and password information must be
configured on the RADIUS server.
•
For local authentication, the username and password information must be configured on the
switch and the service type must be set to
lan-access
.
For configuration of the RADIUS client, see
AAA
in the
Security Configuration Guide
.
Configuring 802.1X globally
Follow these steps to configure 802.1X globally:
To do…
Use the command…
Remarks
1.
Enter system view
system-view
—
2.
Enable 802.1X globally
dot1x
Required
Disabled by default
3.
Specify the authentication
method
dot1x
authentication-method
{
chap
|
eap
|
pap
}
Optional
CHAP by default
4.
Specify the port authorization
mode for specified or all ports
dot1x
port-control
{
authorized-force
|
auto
|
unauthorized-force
} [
interface
interface-list
]
Optional
auto
by default
5.
Specify the port access control
method for specified or all
ports
dot1x
port-method
{
macbased
|
portbased
} [
interface
interface-list
]
Optional
macbased
by default
6.
Set the maximum number of
users for specified or all ports
dot1x
max-user
user-number
[
interface
interface-list
]
Optional
1024 by default
7.
Set the maximum number of
attempts to send an
authentication request to a
client
dot1x retry
max-retry-value
Optional
2 by default