![H3C S5120-SI Series Скачать руководство пользователя страница 372](http://html2.mh-extra.com/html/h3c/s5120-si-series/s5120-si-series_operation-manual_3711174372.webp)
1-19
To do…
Use the command…
Remarks
Configure the Auth-Fail VLAN
for the port
dot1x auth-fail vlan
authfail-vlan-id
Required
By default, a port is configured
with no Auth-Fail VLAN.
Different ports can be configured with different Auth-Fail VLANs, but a port can be configured with only
one Auth-Fail VLAN.
Displaying and Maintaining 802.1X
To do…
Use the command…
Remarks
Display 802.1X session
information, statistics, or
configuration information of
specified or all ports
display dot1x
[
sessions
|
statistics
] [
interface
interface-list
]
Available in any view
Clear 802.1X statistics
reset dot1x statistics
[
interface interface-list
]
Available in user view
802.1X Configuration Example
Network requirements
z
It is required to use the access control method of
macbased
on the port GigabitEthernet1/0/1 to
control clients.
z
All clients belong to default domain aabbcc.net, which can accommodate up to 30 users. RADIUS
authentication is performed at first, and then local authentication when no response from the
RADIUS server is received. If the RADIUS accounting fails, the device gets users offline.
z
A server group with two RADIUS servers is connected to the switch. The IP addresses of the
servers are 10.1.1.1 and 10.1.1.2 respectively. Use the former as the primary
authentication/secondary accounting server, and the latter as the secondary
authentication/primary accounting server.
z
Set the shared key for the device to exchange packets with the authentication server as name, and
that for the device to exchange packets with the accounting server as money.
z
Specify the device to try up to five times at an interval of 5 seconds in transmitting a packet to the
RADIUS server until it receives a response from the server, and to send real time accounting
packets to the accounting server every 15 minutes.
z
Specify the device to remove the domain name from the username before passing the username to
the RADIUS server.
z
Set the username of the 802.1X user as
localuser
and the password as
localpass
and specify to
use clear text mode. Enable the idle cut function to get the user offline whenever the user remains
idle for over 20 minutes.
Содержание S5120-SI Series
Страница 61: ...7 8 Sysname ip http acl 2030...
Страница 138: ...2 10 PORT VLAN MODE GigabitEthernet1 0 1 2 MANUAL...
Страница 186: ...1 46 Instance Vlans Mapped 0 1 to 9 11 to 19 21 to 29 31 to 4094 1 10 2 20 3 30...
Страница 218: ...ii Displaying and Maintaining BOOTP Client Configuration 4 2 BOOTP Client Configuration Example 4 3...
Страница 255: ...1 12...
Страница 381: ...ii Troubleshooting RADIUS 1 32...
Страница 577: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...