67. 802.1X Commands
650
Dynamic VLAN using IEEE 802.1X
In a static VLAN, the destination VLAN is fixed for each port. Meanwhile, in a dynamic
VLAN, the destination VLAN is determined based on the client MAC address
information regardless of a port to be connected.
There are several ways to configure dynamic VLAN. One of them is to use IEEE 802.1X
RADIUS server information. If the client's VLAN information is registered in the
RADIUS server, the VLAN information is retrieved during authentication, allowing for
accessing the VLAN to which the client belongs from any port.
Figure 67-4 Dynamic VLAN
enable 802.1x
disable 802.1x
create 802.1x user <username 15>
delete 802.1x user <username 15>
show 802.1x user
config 802.1x auth_protocol [local | radius_eap]
show 802.1x {[auth_state | auth_configuration] ports {<portlist>}}
config 802.1x capability ports [<portlist> | all] [authenticator | none]
config 802.1x fwd_pdu ports [<portlist> | all] [enable | disable]
config 802.1x fwd_pdu system [enable | disable]
config 802.1x auth_parameter ports [<portlist> | all] [default | {direction [both | in] | port_control
[force_unauth | auto | force_auth] | quiet_period <sec 0-65535> | tx_period <sec 1-65535>
| supp_timeout <sec 1-65535> | server_timeout <sec 1-65535> | max_req <value 1-10> |
reauth_period <sec 1-65535> | max_users [<value 1-448> | no_limit] | enable_reauth [enable
| disable]}(1)]
config 802.1x authorization attributes radius [enable | disable]
config 802.1x init [port_based ports [<portlist> | all] | mac_based ports [<portlist> | all]
{mac_address <macaddr>}]
config 802.1x max_users [<value 1-448> | no_limit]
config 802.1x reauth [port_based ports [<portlist> | all] |mac_based ports [<portlist> | all]
{mac_address <macaddr>}]
create 802.1x guest_vlan <vlan_name 32>
delete 802.1x guest_vlan <vlan_name 32>
config 802.1x guest_vlan ports [<portlist> | all] state [enable | disable]
Содержание ZEQUO 2200
Страница 3: ...3 ...
Страница 86: ...7 ARP Commands 86 ...
Страница 93: ...9 Auto Configuration Commands 93 ...
Страница 273: ...30 IPv6 NDP Commands 273 ...
Страница 330: ...36 LLDP Commands 330 ...
Страница 361: ...39 MAC based Access Control Commands 361 ...
Страница 435: ...45 Network Monitoring Commands 435 Zxxx0 admin clear attack_log Command clear attack_log Success Zxxx0 admin ...
Страница 461: ...49 Protocol VLAN Commands 461 ...
Страница 483: ...50 QoS Commands 483 ...
Страница 504: ...53 SNMPv1 v2 v3 Commands 504 Only Administrator level users can issue this command ...
Страница 523: ...53 SNMPv1 v2 v3 Commands 523 ...
Страница 562: ...57 Subnet VLAN Commands 562 ...