1-16
information about the
user-name-format
command, refer to
AAA Commands
in the
Security
Volume.
z
If the username of a client contains the version number or one or more blank spaces, you can
neither retrieve information nor disconnect the client by using the username. However, you can use
items such as IP address and connection index number to do so.
z
The online user handshake security function is implemented based on the online user handshake
function. To bring the security function into effect, keep the online user handshake function
enabled.
z
The iNode client software and iMC server are recommended to ensure the normal operation of the
online user handshake security function.
z
Once enabled with the 802.1X multicast trigger function, a port sends multicast trigger messages to
the client periodically to initiate authentication.
z
For a user-side device sending untagged traffic, the voice VLAN function and 802.1X are mutually
exclusive and cannot be configured together on the same port. For details about voice VLAN, refer
to
VLAN Configuration
in the
Access Volume
.
z
Configuring an 802.1X Guest VLAN
z
The guest VLAN function and the free IP function in EAD fast deployment are mutually exclusive on
a port.
z
If the traffic from a user-side device carries VLAN tags and the 802.1X authentication and guest
VLAN functions are configured on the access port, you are recommended to configure different
VLAN IDs for the voice VLAN, default VLAN of the port, and 802.1X guest VLAN. This is to ensure
the normal use of the functions.
Configuration prerequisites
z
Create the VLAN to be specified as the guest VLAN.
z
To configure a port-based guest VLAN, make sure that the port access control method is
portbased
, and the 802.1X multicast trigger function is enabled.
z
To configure a MAC-based guest VLAN, make sure that the port access control method is
macbased
and the MAC VLAN function is enabled on the port. For the MAC VLAN configuration,
refer to
VLAN Configuration
in the
Access Volume
.
Configuration procedure
Follow these steps to configure a port-based guest VLAN:
To do…
Use the command…
Remarks
Enter system view
system-view
—
In system
view
dot1x guest-vlan guest-vlan-id
[
interface
interface-list
]
Configure the
guest VLAN
for specified
or all ports
In Ethernet
interface view
interface interface-type
interface-number
Required
Use either approach.
By default, a port is configured
with no guest VLAN.
Содержание S5500-SI Series
Страница 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Страница 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Страница 250: ...3 3 SwitchB system view SwitchB interface vlan interface 1 SwitchB Vlan interface1 ip address dhcp alloc...
Страница 310: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1...
Страница 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Страница 493: ...2 8...
Страница 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...