Operation Manual - Security
Quidway S3000-EI Series Ethernet Switches
Chapter 1 802.1x Configuration
Huawei Technologies Proprietary
1-15
Table 1-17
Enabling/disabling a quiet-period timer
Operation
Command
Enable a quiet-period timer
dot1x quiet-period
Disable a quiet-period timer
undo dot1x quiet-period
By default,
quiet-period
timer is disabled.
1.3 Displaying and Debugging 802.1x
After the above configuration, execute
display
command in any view to display the
running of the VLAN configuration, and to verify the effect of the configuration. Execute
reset
command in user view to reset 802.1x statistics. Execute
debugging
command
in user view to debug 802.1x.
Table 1-18
Displaying and debugging 802.1x
Operation
Command
Display the configuration, running and
statistics information of 802.1x
display dot1x
[
sessions
|
statistics
]
[
interface interface-list
]
Reset the 802.1x statistics information
reset dot1x statistics
[
interface
interface-list
]
Enable the error/event/packet/all
debugging of 802.1x
debugging dot1x
{
error
|
event
|
packet
|
all
}
Disable the error/event/packet/all
debugging of 802.1x.
undo debugging dot1x
{
error
|
event
|
packet
|
all
}
1.4 802.1x Configuration Example
I. Networking requirements
As shown in the following figure, the workstation of a user is connected to the port
Ethernet 0/1 of the Switch.
The switch administrator will enable 802.1x on all the ports to authenticate the
supplicants so as to control their access to the Internet. The access control mode is
configured as based on the MAC address
All the supplicants belong to the default domain huawei163.net, which can contain up to
30 users. RADIUS authentication is performed first. If there is no response from the
RADIUS server, local authentication will be performed. For accounting, if the RADIUS
server fails to account, the user will be disconnected. In addition, when the user is
accessed, the domain name does not follow the user name. Normally, if the user’s
traffic is less than 2kbps consistently over 20 minutes, he will be disconnected.