80
802.1X configuration task list
Tasks at a glance
(Required.)
(Required.)
Enabling EAP relay or EAP termination
(Optional.)
Setting the port authorization state
(Optional.)
Specifying an access control method
(Optional.)
Setting the maximum number of concurrent 802.1X users on a port
(Optional.)
Setting the maximum number of authentication request attempts
(Optional.)
Setting the 802.1X authentication timeout timers
(Optional.)
Configuring the online user handshake feature
(Optional.)
Configuring the authentication trigger feature
(Optional.)
Specifying a mandatory authentication domain on a port
(Optional.)
(Optional.)
Enabling the periodic online user reauthentication feature
(Optional.)
Configuring an 802.1X guest VLAN
(Optional.)
Enabling 802.1X guest VLAN assignment delay
(Optional.)
Configuring an 802.1X Auth-Fail VLAN
(Optional.)
Configuring an 802.1X critical VLAN
(Optional.)
Enabling 802.1X critical voice VLAN
(Optional.)
Sending 802.1X protocol packets out of a port without VLAN tags
(Optional.)
Specifying supported domain name delimiters
(Optional.)
Configuring the EAD assistant feature
Enabling 802.1X
When you enable 802.1X, follow these guidelines:
•
If the PVID is a voice VLAN, the 802.1X feature cannot take effect on the port. For more
information about voice VLANs, see
Layer 2—LAN Switching Configuration Guide
.
•
Do not enable 802.1X on a port that is in a link aggregation or service loopback group.
To enable 802.1X:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable 802.1X globally.
dot1x
By default, 802.1X is disabled
globally.
3.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
4.
Enable 802.1X on a port.
dot1x
By default, 802.1X is disabled
on a port.