![Juniper JUNOS OS 10.3 - SOFTWARE Manual Download Page 2705](http://html.mh-extra.com/html/juniper/junos-os-10-3-software/junos-os-10-3-software_manual_20327932705.webp)
6.
Configure the IP address of the EX Series switch in the list of clients on the RADIUS
server. For specifics on configuring the RADIUS server, consult the documentation for
your server.
Related
Documentation
Configuring 802.1X Interface Settings (CLI Procedure) on page 2609
•
•
Configuring 802.1X Authentication (J-Web Procedure) on page 2610
•
Configuring MAC RADIUS Authentication (CLI Procedure) on page 2613
•
Configuring 802.1X RADIUS Accounting (CLI Procedure) on page 2617
Configuring 802.1X Interface Settings (CLI Procedure)
IEEE 802.1X authentication provides network edge security, protecting Ethernet LANs
from unauthorized user access by blocking all traffic to and from a supplicant (client) at
the interface until the supplicant's credentials are presented and matched on the
authentication server
(a RADIUS server). When the supplicant is authenticated, the switch
stops blocking access and opens the interface to the supplicant.
NOTE:
You can also specify an 802.1X exclusion list to specify supplicants
can that can bypass authentication and be automatically connected to the
LAN. See “Configuring Static MAC Bypass of Authentication (CLI Procedure)”
on page 2612.
Before you begin, specify the RADIUS server or servers to be used as the authentication
server. See “Specifying RADIUS Server Connections on an EX Series Switch (CLI
Procedure)” on page 2608.
To configure 802.1X on an interface:
1.
Configure the supplicant mode as
single
(authenticates the first supplicant),
single-secure
(authenticates only one supplicant), or
multiple
(authenticates multiple
supplicants):
[edit protocols dot1x]
user@switch#
set authenticator interface ge-0/0/5
supplicant
multiple
2.
Enable reauthentication and specify the reauthentication interval:
[edit protocols dot1x]
user@switch#
set authenticator interface ge-0/0/5/0
reauthentication
interval 5
3.
Configure the interface timeout value for the response from the supplicant:
[edit protocols dot1x]
user@switch#
set authenticator interface ge-0/0/5
supplicant-timeout
5
4.
Configure the timeout for the interface before it resends an authentication request to
the RADIUS server:
[edit protocols dot1x]
user@switch#
set authenticator interface ge-0/0/5
server-timeout
5
2609
Copyright © 2010, Juniper Networks, Inc.
Chapter 83: Configuring Access Control
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...