Configuration Guide
802.1x Configuration
Configuring Dynamic Acl Assignment
802.1x supports ACL assignment from server and dynamic installation of the assigned ACL. Our product support installing
acl by default. They will install acl dynamically on condition that the allowed acl is set on the server and is assigned after
the successful user authentication.
To implement dynamic acl assignment, you need to set the port as mac-based authentication mode or port-based
single-user authentication mode. For the configuration, please refer to the related command configuration manual.
In single-host authentication mode, it supports to renew acl when reauthenticating. That is, acl takes effect
when the authenticated user sets acl on the server and reauthenticates.
The mac-based authentication mode does not support ACL update when re-authenticating. That is to say,
ACL of the authenticated user can only be assigned once. The new acl is ignored and the original acl
remains if the acl changes when re-authenticating.
Supported acl type: extension type which can explain acl function on our switch.
Execute the following command if you need to support dynamic acl assignment on the server which is not authenticated
by our company.
Ruijie#
configure terminal
Ruijie(config)#
radius vendor-specific extend
Configuring Dot1x MAC Authentication Bypass
GUEST VLAN provides a method of network accessing without the 802.1x authentication client, but this technology is
unable to determine whether the access device is secure or insecure. In some conditions, for the network management
and security, although there is no 802.1x authentication client, the administrator still needs to control the validity of the
access device. MAB (MAC Authentication Bypass) provides a solution for this application.
With the MAB function enabled on the 802.1x authentication port, the authentication request packets are sent
continuously to the port and the client response is expected. If there is no client response within the time of
“tx-period*reauth-max”, the MAC address learned on the 802.1x authentication port will be monitored, and the
authentication will be initiated by sending the username (the learned MAC address) and keyword to the server. It
determines whether the learned MAC address is accessible to the network or not according to the returned authentication
result from the server.
To configure the MAB function, run the following commands:
Command
Function
Ruijie(config)#
interface
interface-id
Enter interface configuration mode.
Ruijie(config-if-
type ID
)#
dot1x
mac
-
auth
-
bypass
Set the dot1x MAC authentication bypass.
Ruijie#
show running-config
Show all configurations.
Summary of Contents for RG-S2900G-E Series
Page 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Page 91: ...Configuration Guide Configuring PoE Configuration ...
Page 133: ...Configuration Guide EEE Configuration ...
Page 319: ...Configuration Guide QinQ Configuration ...
Page 408: ......
Page 409: ...IP Routing Configuration 1 Static Route Configuration ...
Page 412: ......
Page 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Page 757: ......
Page 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Page 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Page 901: ...Configuration Guide ERSPAN Configuration ...
Page 902: ...Web based Configuration 1 Web based Configuration ...