1-13
authentication domain for authentication, authorization, and accounting of all 802.1X users on the port.
In this way, users accessing the port cannot use any account in other domains.
Meanwhile, for EAP relay mode 802.1X authentication that uses certificates, the certificate of a user
determines the authentication domain of the user. However, you can specify different mandatory
authentication domains for different ports even if the user certificates are from the same certificate
authority (that is, the user domain names are the same). This allows you to deploy 802.1X access
policies flexibly.
802.1X Configuration Task List
Complete the following tasks to configure 802.1X:
Task
Remarks
802.1X Basic Configuration
Required
Enabling the Online User Handshake Function
Optional
Enabling the Proxy Detection Function
Optional
Enabling the Multicast Trigger Function
Optional
Enabling the Unicast Trigger Function
Optional
Specifying a Mandatory Authentication Domain for a Port
Optional
Enabling the Quiet Timer Function
Optional
Enabling the Re-Authentication Function
Optional
Configuring a Guest VLAN
Optional
Configuring an Auth-Fail VLAN
Optional
802.1X Basic Configuration
Configuration Prerequisites
802.1X provides a method for implementing user identity authentication. However, 802.1X cannot
implement the authentication scheme solely by itself. RADIUS or local authentication must be
configured to work with 802.1X.
z
Configure the ISP domain to which the 802.1X user belongs and the AAA scheme to be used (that
is, local authentication or RADIUS).
z
For remote RADIUS authentication, the username and password information must be configured
on the RADIUS server.
z
For local authentication, the username and password information must be configured on the device
and the service type must be set to
lan-access
.
For detailed configuration of the RADIUS client, refer to
AAA Configuration
in the
Security Volume
.
Configuring 802.1X Globally
Follow these steps to configure 802.1X globally:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...