Managing 802.1X Encryption Keys - D-Link DWS-1008 User Manual

Wireless 8 port switch with poe
Hide thumbs Also See for DWS-1008:
Table of Contents

Advertisement

DWS-1008 User's Manual
For example, the following command forces port 19 to unconditionally authenticate all 802.1X
authentication attempts with an EAP success message:
DWS-1008# set dot1x port-control forceauth 19
success: authcontrol for 19 is set to FORCE-AUTH.
Similarly, the following command forces port 12 to unconditionally reject any 802.1X attempts
with an EAP failure message:
DWS-1008# set dot1x port-control forceunauth 12
success: authcontrol for 12 is set to FORCE-UNAUTH.
The set dot1x port-control command is overridden by the set dot1x authcontrol command.
The clear dot1x port-control command returns port control to the default auto value.
Type the following command to reset port control for all wired authentication ports:
DWS-1008# clear dot1x port-control
success: change accepted.

Managing 802.1X Encryption Keys

By default, the switch sends encryption key information to a wireless supplicant (client)
in an Extensible Authentication Protocol over LAN (EAPoL) packet after authentication is
successful. You can disable this feature or change the time interval for key transmission.
The secret Wired-Equivalent Privacy protocol (WEP) keys used by MSS on access points for
broadcast communication on a VLAN are automatically rotated (rekeyed) every 30 minutes
to maintain secure packet transmission. You can disable WEP key rotation for debugging
purposes, or change the rotation interval.
Enabling 802.1X Key Transmission
The following command enables or disables the transmission of key information to the
supplicant (client) in EAPoL key messages, after authentication:
set dot1x key-tx {enable | disable}
Key transmission is enabled by default.
The switch sends EAPoL key messages after successfully authenticating the supplicant
(client) and receiving authorization attributes for the client. If the client is using dynamic WEP,
the EAPoL Key messages are sent immediately after authorization.
Type the following command to reenable key transmission:
DWS-1008# set dot1x key-tx enable
success: dot1x key transmission enabled.
D-Link Systems, Inc.
Managing 802.1X
329

Advertisement

Table of Contents
loading

Table of Contents