![H3C S5500-SI Series Скачать руководство пользователя страница 603](http://html2.mh-extra.com/html/h3c/s5500-si-series/s5500-si-series_operation-manual_3758650603.webp)
1-15
will take effect instead of that specified on the device. The re-authentication interval assignment
varies by server type. Refer to the specific authentication server implementation for further details.
Configuring 802.1X for a Port
Enabling 802.1X for a port
Follow these steps to enable 802.1X for a port:
To do…
Use the command…
Remarks
Enter system view
system-view
—
In system view
dot1x
interface
interface-list
interface
interface-type
interface-number
Enable
802.1X for
one or more
ports
In Ethernet
interface view
dot1x
Required
Use either approach.
Disabled by default
Configuring 802.1X parameters for a port
Follow these steps to configure 802.1X parameters for a port:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter Ethernet interface view
interface
interface-type
interface-number
—
Set the port access control
mode for the port
dot1x
port-control
{
authorized-force
|
auto
|
unauthorized-force
}
Optional
auto
by default
Set the port access control
method for the port
dot1x
port-method
{
macbased
|
portbased
}
Optional
macbased
by default
Set the maximum number of
users for the port
dot1x
max-user user-number
Optional
256 by default
Enable online user handshake
dot1x handshake
Optional
Enabled by default
Enable the online handshake
security function
dot1x handshake secure
Optional
Disabled by default
Enable multicast trigger
dot1x multicast-trigger
Optional
Enabled by default
Specify the mandatory
authentication domain for the
port
dot1x mandatory-domain
domain-name
Optional
No mandatory authentication
domain is specified by default.
Note that:
z
Enabling 802.1X on a port is mutually exclusive with adding the port to an aggregation group.
z
In EAP relay authentication mode, the device encapsulates the 802.1X user information in the EAP
attributes of RADIUS packets and sends the packets to the RADIUS server for authentication. In
this case, you can configure the
user-name-format
command but it does not take effect. For
Содержание S5500-SI Series
Страница 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Страница 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Страница 250: ...3 3 SwitchB system view SwitchB interface vlan interface 1 SwitchB Vlan interface1 ip address dhcp alloc...
Страница 310: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1...
Страница 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Страница 493: ...2 8...
Страница 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...