75
Task
Remarks
Setting the port authorization state
Optional
Specifying an access control method
Optional
Setting the maximum number of concurrent 802.1X users on a port
Optional
Setting the maximum number of authentication request attempts
Optional
Setting the 802.1X authentication timeout timers
Optional
Configuring the online user handshake function
Optional
Configuring the authentication trigger function
Optional
Specifying a mandatory authentication domain on a port
Optional
Optional
Enabling the periodic online user re-authentication function
Optional
Configuring an 802.1X guest VLAN
Optional
Optional
Enabling 802.1X
NOTE:
If the default VLAN of a port is a voice VLAN, the 802.1X function cannot take effect on the port. For more
information about voice VLANs, see the
Layer 2
—
LAN Switching Configuration Guide.
802.1X is mutually exclusive with link aggregation group configuration on a port.
Follow these steps to enable 802.1X on a port:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable 802.1X globally
dot1x
Required
Disabled by default.
Enable 802.1X
on a port
In system view
dot1x
interface
interface-list
Required
Use either approach.
Disabled by default.
In Layer 2
Ethernet
interface view
interface
interface-type
interface-number
dot1x
Specifying EAP relay or EAP termination
When configuring EAP relay or EAP termination, consider the following factors:
The support of the RADIUS server for EAP packets
The authentication methods supported by the 802.1X client and the RADIUS server
If the client is using only MD5-Challenge EAP authentication or the "username + password" EAP
authentication initiated by an iNode 802.1X client, you can use both EAP termination and EAP relay. To