![Huawei Quidway S5600 Operation Manual Download Page 515](http://html.mh-extra.com/html/huawei/quidway-s5600/quidway-s5600_operation-manual_169841515.webp)
Operation Manual – 802.1x
Quidway S5600 Series Ethernet Switches-Release 1510
Chapter 1 802.1x Configuration
Huawei Technologies Proprietary
1-12
Note:
The client-version-checking function needs the support of Huawei’s 802.1x client
program.
III. The Guest VLAN function
The Guest VLAN function enables supplicant systems that do not pass the
authentication to access a LAN in a restrained way.
With the Guest VLAN function enabled, supplicant systems that do not have 802.1x
client installed can access specific network resources. They can also upgrade their
802.1x clients without being authenticated.
With this function enabled:
z
The switch multicasts trigger packets to all 802.1x-enabled ports.
z
After the maximum number retries have been made and there are still ports that
have not sent any response back, the switch will then add these ports into the
Guest VLAN.
z
Users belonging to the Guest VLAN can access the resources of the Guest VLAN
without being authenticated. But they need to be authenticated before accessing
external resources.
Normally, the Guest VLAN function is coupled with the dynamic VLAN delivery function.
Refer to
AAA&RADIUS&RADIUS&HWTACACS&EAD Operation Manual
for detailed
information about dynamic VLAN assignment function.
1.2 802.1x Configuration
802.1x provides a solution for authenticating users. To implement this solution, you
need to execute 802.1x-related commands. You also need to configure AAA schemes
on switches and to specify the authentication scheme (RADIUS authentication scheme
or local authentication scheme).
ISP domain
configurati on
AAA sc he
Local
aut henticati on
me
RADIUS
scheme
802.1x
configurati on
ISP domain
configurati on
AAA sc he
Local
aut henticati on
me
RADIUS
scheme
802.1x
configurati on
Figure 1-10
802.1x configuration
z
802.1x users use domain names to associate with the ISP domains configured on
switches
z
Configure the AAA scheme (a local authentication scheme or the RADIUS
scheme) to be adopted in the ISP domain.