3Com 5500-SI Configuration Manual page 434

5500 series
Hide thumbs Also See for 5500-SI:
Table of Contents

Advertisement

434
C
21: 802.1
HAPTER
C
X
ONFIGURATION
And that completes the configuration of the new radius server and associating it with
a domain.
Network Login
Network login must first be enabled globally by issuing the command dot1x:
[5500-xx]dot1x
802.1x is enabled globally
(where
is either EI or SI)
xx
Once enabled globally, the network login needs to be enabled on a per port basis.
This can be done in one of two ways:
To enable dot1x on one port, enter the interface of the port and enable dot1x on
the port. For example:
[5500-xx]interface ethernet 1/0/7
[5500-xx-Ethernet1/0/7]dot1x
802.1x is enabled on port Ethernet1/0/7
[5500-xx-Ethernet1/0/7]
To enable dot1x on more than 1 port, enter the global dot1x command as follows:
[5500-xx]dot1x interface Ethernet 1/0/7 to Ethernet 1/0/12 Ethernet
1/0/14 to Ethernet 1/0/20
802.1x is enabled on port Ethernet1/0/7 already
802.1x is enabled on port Ethernet1/0/8
802.1x is enabled on port Ethernet1/0/9
802.1x is enabled on port Ethernet1/0/10
802.1x is enabled on port Ethernet1/0/11
802.1x is enabled on port Ethernet1/0/12
802.1x is enabled on port Ethernet1/0/14
802.1x is enabled on port Ethernet1/0/15
802.1x is enabled on port Ethernet1/0/16
802.1x is enabled on port Ethernet1/0/17
802.1x is enabled on port Ethernet1/0/18
802.1x is enabled on port Ethernet1/0/19
802.1x is enabled on port Ethernet1/0/20
[5500-xx]
802.1x login is now enabled on the port. When a device with an 802.1x client
connects to the port, the user will be challenged for a username and password. The
username should be in the form ìuser@domainî where ìdomainî is the name of the
domain that was created on the Switch. This will tell the Switch which domain, and
subsequently which RADIUS server the user is associated with.
By default, the username sent to the RADIUS server for verification will be in the form
user@domain.
You can send the username without the domain extension to the RADIUS server This
can be changed under the RADIUS scheme as follows:
[5500-xx-radius-NewSchemeName]user-name-format without-domain
Switch Login
The Switch 5500 supports Switch login, to allow multiple users access to the
management interface of the switch.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5500-ei5500g-ei

Table of Contents