3Com 7700 Configuration Manual page 188

Hide thumbs Also See for 7700:
Table of Contents

Advertisement

180
C
9: AAA
HAPTER
AND
RADIUS O
PERATION
By default, 802.1x authentication has not been enabled globally and on any port.
Setting the Port Access Control Mode
The following commands can be used for setting 802.1x access control mode on
the specified port. When no port is specified, the access control mode of all ports
is configured.
Perform the following configurations in system view or Ethernet port view.
Table 2 Set the Port Access Control Mode.
Operation
Set the port access control mode.
Restore the default access control
mode of the port.
By default, access control on the port is auto (automatic identification mode,
which is also called protocol control mode). That is, the initial state of the port is
unauthorized. It only permits EAPoL packets receiving/transmitting and does not
permit the user to access the network resources. If the authentication flow is
passed, the port will be switched to the authorized state and permit the user to
access the network resources. This is the most common case.
Setting Port Access Control Method
The following commands are used for setting 802.1x access control method on
the specified port. When no port is specified in system view, the access control
method of port is configured globally.
Perform the following configurations in system view or Ethernet port view.
Table 3 Set Port Access Control Method
Operation
Set port access control method
Restore the default port access
control method
By default, 802.1x authentication method on the port is MAC-based. That is,
authentication is performed based on MAC addresses.
Checking the Users that Log on the Switch by Proxy
The following commands are used for checking the users that log on by proxy.
Perform the following configurations in system view or Ethernet port view.
Table 4 Check the Users that Log on the Switch by Proxy
Operation
Enable the check for access
users by proxy
Cancel the check for access
users by proxy
Command
dot1x port-control {authorized- force |
unauthorized-force | auto} [interface interface-list]
undo dot1x port-control [interface interface-list]
Command
dot1x port-method {macbased | portbased}
[interface interface-list]
undo dot1x port-method [interface interface-list]
Command
dot1x supp-proxy-check {logoff | trap} [interface
interface-list]
undo dot1x supp-proxy-check {logoff | trap} [interface
interface-list]

Advertisement

Table of Contents
loading

Table of Contents