101
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
3.
Enable the device to send
802.1X protocol packets
out of the port without
VLAN tags.
dot1x eapol untag
By default, the device can send 802.1X
EAPOL packets out of a port with VLAN
tags.
Setting the maximum number of 802.1X
authentication attempts for MAC authenticated
users
When a port uses both 802.1X authentication and MAC authentication, the device accepts 802.1X
authentication requests from MAC authenticated users. If a MAC authenticated user passes 802.1X
authentication, the user will come online as an 802.1X user. If the user fails 802.1X authentication,
the user continues to make 802.1X authentication attempts depending on client configuration.
Perform this task to limit the number of 802.1X authentication attempts made by a MAC
authenticated user.
To set the maximum number of 802.1X authentication attempts for MAC authenticated users on a
port:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
3.
Set the maximum number
of 802.1X authentication
attempts for MAC
authenticated users on
the port.
dot1x after-mac-auth
max-attempt
max-attempts
By default, the number of 802.1X
authentication attempts for MAC
authenticated users is not limited on a
port.
Configuring the EAD assistant feature
When you configure the EAD assistant feature, follow these restrictions and guidelines:
•
You must disable MAC authentication and port security globally before you enable the EAD
assistant feature.
•
To make the EAD assistant feature take effect on an 802.1X-enabled port, you must set the port
authorization mode to
auto
.
•
When global MAC authentication or port security is enabled, the free IP does not take effect.
•
If you use free IP, guest VLAN, and Auth-Fail VLAN features together, make sure the free IP
segments are in both guest VLAN and Auth-Fail VLAN.
•
The server that provides the redirect URL must be on the free IP accessible to unauthenticated
users.
•
To avoid using up ACL resources when a large number of EAD users exist, you can shorten the
EAD rule timer.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...