89
Step Command Remarks
1.
Enter system
view.
system-view
N/A
2.
Configure EAP
relay or EAP
termination.
dot1x
authentication-method
{
chap
|
eap
|
pap
}
By default, the access device performs EAP
termination and uses CHAP to communicate with
the RADIUS server.
Specify the
eap
keyword to enable EAP relay.
Specify the
chap
or
pap
keyword to enable
CHAP-enabled or PAP-enabled EAP termination.
NOTE:
If EAP relay mode is used, the
user-name-format
command configured in RADIUS scheme view
does not take effect. The access device sends the authentication data from the client to the server
without any modification.
Setting the port authorization state
The port authorization state determines whether the client is granted access to the network. You can
control the authorization state of a port by using the
dot1x port-control
command and the following
keywords:
•
authorized-force
—Places the port in the authorized state, enabling users on the port to access
the network without authentication.
•
unauthorized-force
—Places the port in the unauthorized state, denying any access requests
from users on the port.
•
auto
—Places the port initially in unauthorized state to allow only EAPOL packets to pass. After
a user passes authentication, sets the port in the authorized state to allow access to the
network. You can use this option in most scenarios.
To set the authorization state of a port:
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Ethernet interface
view.
interface
interface-type
interface-number
N/A
3.
Set the port authorization
state.
dot1x port-control
{
authorized-force
|
auto
|
unauthorized-force
}
By default, the
auto
state
applies.
Specifying an access control method
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Ethernet interface
view.
interface
interface-type
interface-number
N/A
3.
Specify an access control
method.
dot1x port-method
{
macbased
|
portbased
}
By default, MAC-based access
control applies.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...