196
C
HAPTER
11: 802.1X C
ONFIGURATION
By default, the quiet-period timer is disabled.
Displaying and
Debugging 802.1X
After the above configuration, execute
display
command in any view to display
the running of the VLAN configuration, and to verify the effect of the
configuration. Execute
reset
command in User View to reset 802.1X statistics.
Execute
debugging
command in User View to debug 802.1X.
Table 199
Displaying and Debugging 802.1X
Auto QoS
Auto QoS uses the Filter-ID standard RADIUS attribute.
Table 200
Auto QoS
802.1X Configuration
Example
Networking Requirements
As shown in the following figure, the workstation of a user is connected to the
port Ethernet 1/0/1 of the Switch.
The switch administrator will enable 802.1X on all the ports to authenticate the
users so as to control their access to the Internet. The access control mode is
configured as based on the MAC address
All the users belong to the default domain
3com163.net
, which can contain up to
30 users. RADIUS authentication is performed first. If there is no response from the
RADIUS server, local authentication will be performed. For accounting, if the
RADIUS server fails to account, the user will be disconnected. In addition, when
the user is accessed, the domain name does not follow the user name. Normally, if
the user's traffic is less than 2 kbps consistently over 20 minutes, they will be
disconnected.
A server group, consisting of two RADIUS servers at 10.11.1.1 and 10.11.1.2
respectively, is connected to the switch. The former one acts as the
primary-authentication/second-accounting server. The latter one acts as the
secondary-authentication/primary-accounting server. Set the encryption key as
“name” when the system exchanges packets with the authentication RADIUS
server and “money” when the system exchanges packets with the accounting
RADIUS server. Configure the system to retransmit packets to the RADIUS server if
no response is received within 5 seconds. Retransmit the packet no more than 5
times in all. Configure the system to transmit a real-time accounting packet to the
Disable a quiet-period timer
undo dot1x quiet-period
Operation
Command
Operation
Command
Display the configuration, running
and statistics information of 802.1X
display dot1x [ sessions | statistics
] [ interface
interface_list
]
Reset the 802.1X statistics
information
reset dot1x statistics [ interface
interface_list
]
Enable the error/event/packet/all
debugging of 802.1X
debugging dot1x { error | event |
packet | all }
Disable the error/event/packet/all
debugging of 802.1X.
undo debugging dot1x { error | event
| packet | all }
Auto QoS
Return String
Comment
Filter-id
student
QoS profile name
Содержание Switch 4500 26-Port
Страница 16: ...14 ABOUT THIS GUIDE...
Страница 58: ...56 CHAPTER 2 PORT OPERATION...
Страница 104: ...102 CHAPTER 5 NETWORK PROTOCOL OPERATION...
Страница 130: ...128 CHAPTER 6 IP ROUTING PROTOCOL OPERATION...
Страница 154: ...152 CHAPTER 7 ACL CONFIGURATION...
Страница 228: ...226 CHAPTER 11 802 1X CONFIGURATION...
Страница 250: ...248 CHAPTER 14 DEVICE MANAGEMENT...
Страница 280: ...278 CHAPTER 15 SYSTEM MAINTENANCE AND DEBUGGING...
Страница 312: ...310 CHAPTER 18 NTP CONFIGURATION...
Страница 340: ...338 CHAPTER 19 SSH TERMINAL SERVICES...
Страница 350: ...348 CHAPTER 20 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Страница 388: ...386 APPENDIX B RADIUS SERVER AND RADIUS CLIENT SETUP...