Configuring 802.1X
185
The EAPoL-Encapsulated-ASF-Alert is related to the network management
information and terminated by the Authenticator.
Although 802.1X provides user ID authentication, 802.1X itself is not enough to
implement the scheme. The administrator of the access device should configure
the AAA scheme by selecting RADIUS or local authentication to assist 802.1X to
implement the user ID authentication. For detailed description of AAA, refer to the
corresponding AAA configuration.
Implementing 802.1X on
the Switch
The Switch 4500 Family not only supports the port access authentication method
regulated by 802.1X, but also extends and optimizes it in the following way:
■
Support to connect several End Stations in the downstream via a physical port.
■
The access control (or the user authentication method) can be based on port or
MAC address.
■
In this way, the system becomes much securer and easier to manage.
Configuring 802.1X
The configuration tasks of 802.1X itself can be fulfilled in System View of the
Ethernet switch. When the global 802.1X is not enabled, you can configure the
802.1X state of the port. The configured items will take effect after the global
802.1X is enabled.
When 802.1X is enabled on a port, the maximum number of MAC address
learning which is configured by the command
mac-address max-mac-count
cannot be configured on the port, and vice versa.
The main 802.1X configuration includes:
■
Enabling/disabling 802.1X
■
Setting the port access control mode
■
Setting the port access control method
■
Checking the users that log on the Switch via proxy
■
Setting the maximum number of users via each port
■
Setting the Authentication in DHCP Environment
■
Configuring the authentication method for 802.1X user
■
Setting the maximum times of authentication request message retransmission
■
Configuring timers
■
Enabling/disabling a quiet-period timer
Among the above tasks, the first one is compulsory, otherwise 802.1X will not
take any effect. The other tasks are optional. You can perform the configurations
at requirements.
Enabling/Disabling
802.1X
The following command can be used to enable/disable the 802.1X on the
specified port or globally. When it is used in System View ,if the parameter
interface-list
is not specified, 802.1X will be globally enabled. If the parameter
interface-list
is specified, 802.1X will be enabled on the specified port. When
Содержание 400 Family
Страница 12: ......
Страница 16: ...14 ABOUT THIS GUIDE ...
Страница 58: ...56 CHAPTER 2 PORT OPERATION ...
Страница 68: ...66 CHAPTER 3 VLAN OPERATION ...
Страница 98: ...96 CHAPTER 5 NETWORK PROTOCOL OPERATION ...
Страница 124: ...122 CHAPTER 6 IP ROUTING PROTOCOL OPERATION ...
Страница 156: ...154 CHAPTER 8 ACL CONFIGURATION ...
Страница 218: ...216 CHAPTER 11 802 1X CONFIGURATION ...
Страница 298: ...296 CHAPTER 13 PASSWORD CONTROL CONFIGURATION OPERATIONS ...
Страница 336: ...334 APPENDIX B RADIUS SERVER AND RADIUS CLIENT SETUP ...