D-Link DWS-1008 User Manual
8
The default setting is auto, which allows the switch to process 802.1X authentication normally according
to the authentication configuration. Alternatively, you can set a wired authentication port or ports to either
unconditionally authenticate or unconditionally reject all users.
For example, the following command forces port 5 to unconditionally authenticate all 802.1X authentication
attempts with an EAP success message:
DWS-1008#
set dot1x port-control forceauth 5
success: authcontrol for 19 is set to FORCE-AUTH.
Similarly, the following command forces port 6 to unconditionally reject any 802.1X attempts with an EAP
failure message:
DWS-1008#
set dot1x port-control forceunauth 6
success: authcontrol for 12 is set to FORCE-UNAUTH.
The
set dot1x port-control command is overridden by the set dot1x authcontrol command. The clear
dot1x port-control command returns port control to the default auto value.
Type the following command to reset port control for all wired authentication ports:
DWS-1008#
clear dot1x port-control
success: change accepted.
Managing 802.1X Encryption Keys
By default, the switch sends encryption key information to a wireless supplicant (client) in an Extensible
Authentication Protocol over LAN (EAPoL) packet after authentication is successful. You can disable this
feature or change the time interval for key transmission.
The secret Wired-Equivalent Privacy protocol (WEP) keys used by MSS on access points for broadcast
communication on a VLAN are automatically rotated (rekeyed) every 30 minutes to maintain secure
packet transmission. You can disable WEP key rotation for debugging purposes, or change the rotation
interval.
Содержание DWS-1008
Страница 1: ......