176
Syntax
dot1x
port-method
{
macbased
|
portbased
}
undo dot1x
port-method
Default
MAC-based access control applies.
Views
Ethernet interface view
Predefined user roles
network-admin
Parameters
macbased
: Uses MAC-based access control on the port to separately authenticate each user
attempting to access the network. Using this method, when an authenticated user logs off, no other
online users are affected. This keyword is supported only on the following ports:
•
Layer 2 Ethernet ports on the following modules:
HMIM-8GSW.
HMIM-24GSW.
HMIM-24GSWP.
SIC-4GSW.
SIC-4GSWP
•
Fixed Layer 2 Ethernet ports on the following routers:
MSR954 (JH296A/JH297A/JH298A/JH299A/JH373A).
MSR958 (JH300A/JH301A).
MSR2004-24/2004-48.
MSR1002-4/1003-8S.
portbased
: Uses port-based access control on the port. Using this method, once an 802.1X user
passes authentication on the port, any subsequent user can access the network through the port
without authentication. When the authenticated user logs off, all other users are logged off.
Examples
# Configure GigabitEthernet 1/0/1 to implement port-based access control.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] dot1x port-method portbased
Related commands
display dot1x
dot1x quiet-period
Use
dot1x
quiet-period
to enable the quiet timer.
Use
undo dot1x
quiet-period
to disable the quiet timer.
Syntax
dot1x
quiet-period
undo dot1x quiet-period