13-47
Configuring Port-Based and User-Based Access Control (802.1X)
802.1X Open VLAN Mode
Configuring 802.1X Open VLAN Mode.
Use these commands to actually
configure Open VLAN mode. For a listing of the steps needed to prepare the
switch for using Open VLAN mode, refer to “Preparation” on page 13-43.
For example, suppose you want to configure 802.1X port-access with Open
VLAN mode on ports A10 - A20 and:
■
These two static VLANs already exist on the switch:
•
Unauthorized, VID = 80
•
Authorized, VID = 81
■
Your RADIUS server has an IP address of 10.28.127.101. The server uses
rad4all
as a server-specific key string. The server is connected to a port on
the Default VLAN.
■
The switch's default VLAN is already configured with an IP address of
10.28.127.100 and a network mask of 255.255.255.0
Syntax:
aaa port-access authenticator <
port-list
>
[auth-vid <
vlan-id
>]
Configures an existing, static VLAN to be the Authorized-
Client VLAN.
[< unauth-vid <
vlan-id
>]
Configures an existing, static VLAN to be the Unautho-
rized-Client VLAN.
HP Switch(config)# aaa authentication port-access eap-radius
Configures the switch for 802.1X authentication using an EAP-RADIUS server.
HP Switch(config)# aaa port-access authenticator 10-20
Configures ports 10 - 20 as 802.1 authenticator ports.
HP Switch(config)# radius host 10.28.127.101 key rad4all
Configures the switch to look for a RADIUS server with an IP address of 10.28.127.101
and an encryption key of rad4all.
HP Switch(config)# aaa port-access authenticator e 10-20 unauth-vid 80
Configures ports 10 - 20 to use VLAN 80 as the Unauthorized-Client VLAN.
HP Switch(config)# aaa port-access authenticator e 10-20 auth-vid 81
Configures ports 10 - 20 to use VLAN 81 as the Authorized-Client VLAN.
HP Switch(config)# aaa port-access authenticator active
Activates 802.1X port-access on ports you have configured as authenticators.
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......