Raisecom
ISCOM2600G-HI (A) Series Configuration Guide
10 Security
Raisecom Proprietary and Confidential
Copyright © Raisecom Technology Co., Ltd.
438
Step 3
(Optional) configure interface authorization mode to auto. By default, authentication is
required and thus does not need to be configured.
Raisecom(config-gigaethernet1/1/1)#dot1x auth-control auto
Step 4
Enable reauthentication, and configure the timer to 600s.
Raisecom(config-gigaethernet1/1/1)#dot1x reauthentication enable
Raisecom(config-gigaethernet1/1/1)#dot1x timer reauth-period 600
Checking results
Use the
show dot1x
command to show 802.1x configurations on the interface.
Raisecom#show dot1x gigaethernet 1/1/1
802.1x Global Admin State: enable
802.1x Authentication Method: chap
802.1x Authentication Mode: radius
Port gigaethernet1/1/1
--------------------------------------------------------
802.1X Port Admin State: enable
PAE: Authenticator
PortMethod: Portbased
PortControl: Auto
ReAuthentication: enable
KeepAlive: enable
QuietPeriod: 60(s)
ServerTimeout: 100(s)
SuppTimeout: 30(s)
ReAuthPeriod: 600(s)
TxPeriod: 30(s)
KeepalivePeriod: 60(s)
10.8 IP Source Guard
10.8.1 Introduction
IP Source Guard uses a binding table to defend against IP Source spoofing and solve IP
address embezzlement without identity authentication. IP Source Guard can cooperate with
DHCP Snooping to generate dynamic binding. In addition, you can configure static binding
manually. DHCP Snooping filters untrusted DHCP packets by establishing and maintaining
the DHCP binding database.