4-9
Description
Use the
dot1x mandatory-domain
command to specify the mandatory authentication domain for
users accessing the port.
Use the
undo dot1x mandatory-domain
command to remove the mandatory authentication domain.
By default, no mandatory authentication domain is specified.
Note that:
z
When authenticating an 802.1X user trying to access the port, the system selects an
authentication domain in the following order: the mandatory domain, the ISP domain specified in
the username, and the default ISP domain.
z
The specified mandatory authentication domain must exist.
z
On a port configured with a mandatory authentication domain, the user domain name displayed by
the
display connection
command is the name of the mandatory authentication domain. For
detailed information about the
display connection
command, refer to
AAA
Commands
in the
Security Volume
.
Related commands:
display dot1x
.
Examples
# Configure the mandatory authentication domain
my-domain
for 802.1X users on GigabitEthernet
1/0/1.
<Sysname> system-view
[Sysname] interface GigabitEthernet 1/0/1
[Sysname-GigabitEthernet1/0/1] dot1x mandatory-domain my-domain
# After 802.1X user
usera
passes the authentication, display the user connection information on
GigabitEthernet 1/0/1.
[Sysname-GigabitEthernet1/0/1] display connection interface GigabitEthernet 1/0/1
Index=68 ,Username=usera@my-domian
MAC=0015-e9a6-7cfe ,IP=3.3.3.3
Total 1 connection(s) matched.
dot1x max-user
Syntax
In system view:
dot1x
max-user user-number
[
interface interface-list
]
undo dot1x
max-user
[
interface interface-list
]
In Ethernet interface view:
dot1x
max-user user-number
undo dot1x
max-user
View
System view, Ethernet interface view
Содержание E4510-48G
Страница 109: ...2 18 Sysname interface bridge aggregation 1 Sysname Bridge Aggregation1 shutdown ...
Страница 309: ...6 4 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address dhcp alloc ...
Страница 324: ...8 3 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address bootp alloc ...
Страница 530: ...2 5 Sysname mvlan 100 subvlan 10 to 15 ...
Страница 739: ...8 15 Sysname system view Sysname port security trap addresslearned ...
Страница 819: ...13 11 Sysname system view Sysname public key peer key2 import sshkey key pub ...
Страница 857: ...iii 7 Track Configuration Commands 7 1 Track Configuration Commands 7 1 display track 7 1 track nqa 7 2 ...
Страница 914: ...5 17 Sysname reset oam ...
Страница 1064: ...5 30 Slot 2 Set next configuration file successfully ...
Страница 1325: ...21 13 Examples Redirect to member 2 Sysname irf switch to 2 Sysname Slave 2 ...