Configuring 802.1x
395
Setting the User Number
on a Port
The following commands are used for setting the number of users allowed by 802.1x
on a specified port. When no port is specified, all the ports accept the same number
of users.
Perform the following configurations in System View or Ethernet Port View.
Table 416
Setting the Maximum Number of Users using a Specified Port
By default, 802.1x allows up to 256 users on each port for Series 5500 Switches.
Setting the
Authentication in DHCP
Environment
If in a DHCP environment the users configure static IP addresses, you can set 802.1x
to disable the Switch to trigger the user ID authentication over them with the
following command.
Perform the following configurations in System View.
Table 417
Setting the Authentication in DHCP Environment
By default, the Switch can trigger the user ID authentication over the users who
configure static IP addresses in DHCP environment.
Configuring the
Authentication Method
for 802.1x User
The following commands can be used to configure the authentication method for
802.1x user. Three methods are available: PAP authentication (the RADIUS server must
support PAP authentication), CHAP authentication (the RADIUS server must support
CHAP authentication), EAP relay authentication (the Switch sends authentication
information to the RADIUS server in the form of EAP packets directly and the RADIUS
server must support EAP authentication).
Perform the following configurations in System View.
Table 418
Configuring the Authentication Method for 802.1x User
By default, CHAP authentication is used for 802.1x user authentication.
802.1x PEAP
Configuration
Protected extensible authentication protocol (PEAP) authenticates supplicant systems
in a securer way. With PEAP employed, a security channel is created, which is
encrypted and is protected using transport level security (TLS) to ensure integrity. And
authentication is carried out through a new type of EAP (extensible authentication
protocol) negotiation between supplicant systems and authentication servers.
Operation
Command
Set maximum number of users using
specified port
dot1x max-user
user_number
[ interface
interface_list
]
Restore the maximum number of
users on the port to the default value
undo dot1x max-user [ interface
interface_list
]
Operation
Command
Disable the switch to trigger the user ID
authentication over the users who configure
static IP addresses in DHCP environment
dot1x dhcp-launch
Enable the switch to trigger the
authentication over them
undo dot1x dhcp-launch
Operation
Command
Configure authentication method
for 802.1x user
dot1x authentication-method { chap | pap |
eap md5-challenge}
Restore the default authentication
method for 802.1x user
undo dot1x authentication-method
Содержание 5500 SI - Switch - Stackable
Страница 24: ...24 ABOUT THIS GUIDE...
Страница 30: ...30 CHAPTER 1 GETTING STARTED Figure 3 Setting up a New Connection Figure 4 Configuring the Port for Connection...
Страница 50: ...50 CHAPTER 1 GETTING STARTED...
Страница 54: ...54 CHAPTER 2 ADDRESS MANAGEMENT CONFIGURATION...
Страница 78: ...78 CHAPTER 3 PORT OPERATION...
Страница 88: ...88 CHAPTER 4 XRN CONFIGURATION...
Страница 122: ...122 CHAPTER 8 VLAN VPN CONFIGURATION...
Страница 216: ...216 CHAPTER 15 SSH TERMINAL SERVICES...
Страница 268: ...268 CHAPTER 16 IP ROUTING PROTOCOL OPERATION...
Страница 308: ...308 CHAPTER 17 NETWORK PROTOCOL OPERATION...
Страница 349: ...349...
Страница 350: ...350 CHAPTER 18 MULTICAST PROTOCOL...
Страница 522: ...522 CHAPTER 22 FILE SYSTEM MANAGEMENT...
Страница 584: ...584 CHAPTER 30 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Страница 600: ...600 CHAPTER 31 MSDP CONFIGURATION...
Страница 614: ...614 CHAPTER 32 CLUSTERING...
Страница 670: ...670 CHAPTER C AUTHENTICATING THE SWITCH 5500 WITH CISCO SECURE ACS...