
65
# Configure the access control method. By default, an 802.1X-enabled port uses the
MAC-based access control.
[Switch] dot1x port-method macbased interface gigabitethernet 1/0/1
Verifying the configuration
1.
On the host, use the user
dot1x@bbb
to pass 802.1X authentication:
# If the user host runs the Windows XP 802.1X client, configure the network connection
properties as follows:
a.
Click the
Authentication
tab of the properties window.
b.
Select the
Enable IEEE 802.1X authentication for this network
option.
c.
Select MD5 challenge as the EAP type.
d.
Click
OK
.
The user passes authentication after entering the correct username and password on the
authentication page.
# If the user host runs the iNode client, no advanced authentication options are required. The
user can pass authentication after entering username
dot1x@bbb
and the correct password
on the client property page.
2.
On the switch, verify that the server assigns the port connecting the client to VLAN 4 after the
user passes authentication. (Details not shown.)
3.
Display the connection information on the switch.
[Switch] display dot1x connection
Troubleshooting RADIUS
RADIUS authentication failure
Symptom
User authentication always fails.
Analysis
Possible reasons include:
•
A communication failure exists between the NAS and the RADIUS server.
•
The username is not in the
userid
@
isp-name
format, or the ISP domain is not correctly
configured on the NAS.
•
The user is not configured on the RADIUS server.
•
The password entered by the user is incorrect.
•
The RADIUS server and the NAS are configured with different shared keys.
Solution
To resolve the problem:
1.
Check the following items:
{
The NAS and the RADIUS server can ping each other.
{
The username is in the
userid
@
isp-name
format and the ISP domain is correctly configured
on the NAS.
{
The user is configured on the RADIUS server.
{
The correct password is entered.
{
The same shared key is configured on both the RADIUS server and the NAS.
2.
If the problem persists, contact Hewlett Packard Enterprise Support.
Summary of Contents for 10500 series
Page 326: ...312 No duration limit for this SA ...