224
C
HAPTER
17: 802.1
X
C
ONFIGURATION
c
CAUTION:
■
802.1x configurations take effect only after you enable 802.1x both globally
and for specified ports.
■
If you enable 802.1x for a port, you cannot set the maximum number of MAC
addresses that can be learnt for the port. Meanwhile, if you set the maximum
number of MAC addresses that can be learnt for a port, it is prohibited to
enable 802.1x for the port.
■
If you enable 802.1x for a port, it is not available to add the port to an
aggregation group. Meanwhile, if a port has been added to an aggregation
group, it is prohibited to enable 802.1x for the port.
■
Changing the access control method on a port by the
dot1x port-method
command will forcibly log out the online 802.1x users on the port.
■
When a device operates as an authentication server, its authentication method
for 802.1x users cannot be configured as EAP.
■
Handshaking packets need the support of the 3Com-proprietary client. They
are used to test whether or not a user is online.
■
As clients that are not of 3Com do not support the online user handshaking
function, switches cannot receive handshaking acknowledgement packets
Enable
802.1x for
specified
ports
In system
view
dot1x interface
interface-list
Required
By default, 802.1x is disabled on
all ports.
In port
view
interface
interface-type
interface-number
dot1x
quit
Set port access control
mode for specified
ports
dot1x port-control
{
authorized-force
|
unauthorized-force
|
auto
} [
interface
interface-list
]
Optional
By default, an 802.1x-enabled
port operates in the
auto
mode.
Set port access
method for specified
ports
dot1x port
-
method
{
macbased
|
portbased
} [
interface
interface-list
]
Optional
The default port access method is
MAC-address-based (that is, the
macbased
keyword is used by
default).
Set authentication
method for 802.1x
users
dot1x authentication-method
{
chap
|
pap
|
eap
}
Optional
By default, a switch performs
CHAP authentication in EAP
terminating mode.
Enable online user
handshaking
dot1x handshake enable
Optional
By default, online user
handshaking is enabled.
Enter Ethernet port
view
interface interface-type
interface-number
-
Enable the
handshaking packet
secure function
dot1x handshake secure
Optional
By default, the handshaking
secure function is disabled.
Table 162
Configure basic 802.1x functions
Operation
Command Remarks
Содержание Switch 4210 9-Port
Страница 10: ...Password Control Configuration 556 Displaying Password Control 563 Password Control Configuration Example 564 ...
Страница 22: ...20 CHAPTER 1 CLI CONFIGURATION ...
Страница 74: ...72 CHAPTER 3 CONFIGURATION FILE MANAGEMENT ...
Страница 84: ...82 CHAPTER 5 VLAN CONFIGURATION ...
Страница 96: ...94 CHAPTER 8 IP PERFORMANCE CONFIGURATION ...
Страница 108: ...106 CHAPTER 9 PORT BASIC CONFIGURATION ...
Страница 122: ...120 CHAPTER 11 PORT ISOLATION CONFIGURATION ...
Страница 140: ...138 CHAPTER 13 MAC ADDRESS TABLE MANAGEMENT ...
Страница 234: ...232 CHAPTER 17 802 1X CONFIGURATION ...
Страница 246: ...244 CHAPTER 20 AAA OVERVIEW ...
Страница 270: ...268 CHAPTER 21 AAA CONFIGURATION ...
Страница 292: ...290 CHAPTER 26 DHCP BOOTP CLIENT CONFIGURATION ...
Страница 318: ...316 CHAPTER 29 MIRRORING CONFIGURATION ...
Страница 340: ...338 CHAPTER 30 CLUSTER ...
Страница 362: ...360 CHAPTER 33 SNMP CONFIGURATION ...
Страница 368: ...366 CHAPTER 34 RMON CONFIGURATION ...
Страница 450: ...448 CHAPTER 39 TFTP CONFIGURATION ...
Страница 451: ......
Страница 452: ...450 CHAPTER 39 TFTP CONFIGURATION ...
Страница 470: ...468 CHAPTER 40 INFORMATION CENTER ...
Страница 496: ...494 CHAPTER 44 DEVICE MANAGEMENT ...