
65
# Configure the access control method. By default, an 802.1X-enabled port uses the
MAC-based access control.
[Switch] dot1x port-method macbased interface gigabitethernet 1/0/1
Verifying the configuration
1.
On the host, use the user
dot1x@bbb
to pass 802.1X authentication:
# If the user host runs the Windows XP 802.1X client, configure the network connection
properties as follows:
a.
Click the
Authentication
tab of the properties window.
b.
Select the
Enable IEEE 802.1X authentication for this network
option.
c.
Select MD5 challenge as the EAP type.
d.
Click
OK
.
The user passes authentication after entering the correct username and password on the
authentication page.
# If the user host runs the iNode client, no advanced authentication options are required. The
user can pass authentication after entering username
dot1x@bbb
and the correct password
on the client property page.
2.
On the switch, verify that the server assigns the port connecting the client to VLAN 4 after the
user passes authentication. (Details not shown.)
3.
Display the connection information on the switch.
[Switch] display dot1x connection
Troubleshooting RADIUS
RADIUS authentication failure
Symptom
User authentication always fails.
Analysis
Possible reasons include:
•
A communication failure exists between the NAS and the RADIUS server.
•
The username is not in the
userid
@
isp-name
format, or the ISP domain is not correctly
configured on the NAS.
•
The user is not configured on the RADIUS server.
•
The password entered by the user is incorrect.
•
The RADIUS server and the NAS are configured with different shared keys.
Solution
To resolve the problem:
1.
Check the following items:
{
The NAS and the RADIUS server can ping each other.
{
The username is in the
userid
@
isp-name
format and the ISP domain is correctly configured
on the NAS.
{
The user is configured on the RADIUS server.
{
The correct password is entered.
{
The same shared key is configured on both the RADIUS server and the NAS.
2.
If the problem persists, contact Hewlett Packard Enterprise Support.
Содержание 10500 series
Страница 326: ...312 No duration limit for this SA ...