Enabling 802.1X - HP 5120 SI Series Security Configuration Manual

Hide thumbs Also See for 5120 SI Series:
Table of Contents

Advertisement

Task
Specifying EAP relay or EAP termination
Setting the port authorization state
Specifying an access control method
Setting the maximum number of concurrent 802.1X users on a port
Setting the maximum number of authentication request attempts
Setting the 802.1X authentication timeout timers
Configuring the online user handshake function
Configuring the authentication trigger function
Specifying a mandatory authentication domain on a port
Enabling the quiet timer
Enabling the periodic online user re-authentication function
Configuring an 802.1X guest VLAN
Configuring an Auth-Fail VLAN
Specifying supported domain name delimiters

Enabling 802.1X

Configuration guidelines
If the default VLAN of a port is a voice VLAN, the 802.1X function cannot take effect on the port. For
more information about voice VLANs, see the Layer 2
802.1X is mutually exclusive with link aggregation group configuration on a port.
On an 802.1X and MAC authentication enabled port, the EAP packet from an unknown MAC
address immediately triggers 802.1X authentication, and any other type of packet from an
unknown MAC address triggers MAC authentication 30 seconds after its arrival.
Configuration procedure
Follow these steps to enable 802.1X on a port:
To do...
Enter system view
Enable 802.1X globally
Enable 802.1X
on a port
Use the command...
system-view
dot1x
In system view
dot1x interface interface-list
In Layer 2
interface interface-type interface-number
Ethernet
dot1x
interface view
LAN Switching Configuration Guide.
71
Remarks
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Remarks
Required
Disabled by default.
Required
Use either approach.
Disabled by default.

Advertisement

Table of Contents
loading

Table of Contents