Operation Manual - Security
Quidway S3000 Series Ethernet Switches
Chapter 1 802.1x Configuration
1-5
Table 1-2
Set the port access control mode.
Operation
Command
Set the port access control mode.
dot1x
port-control
{
authorized- force
|
unauthorized-force
|
auto
} [
interface
interface-list
]
Restore the default access control mode
of the port.
undo dot1x port-control
[
interface
interface-list
]
By default, the mode of 802.1x performing access control on the port is
auto
(automatic
identification mode, which is also called protocol control mode). That is, the initial state
of the port is unauthorized. It only permits EAPoL packets receiving/transmitting and
does not permit the user to access the network resources. If the authentication flow is
passed, the port will be switched to the authorized state and permit the user to access
the network resources. This is the most common case.
1.2.3 Set Port Access Control Method
The following commands are used for setting 802.1x access control method on the
specified port. When no port is specified in system view, the access control method of
port is configured globally.
Perform the following configurations in system view or Ethernet port view.
Table 1-3
Set port access control method
Operation
Command
Set port access control method
dot1x
port-method
{
macbased
|
portbased
}
[
interface
interface-list
]
Restore the default port access control
method
undo
dot1x
port-method
[
interface
interface-list
]
By default, 802.1x authentication method on the port is
macbased
. That is,
authentication is performed based on MAC addresses.
1.2.4 Check the Users that Log on the Switch via Proxy
The following commands are used for checking the users that log on the switch via
proxy.
Perform the following configurations in system view or Ethernet port view.