Setting The Authentication Method For The 802.1X User - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

2 NAC Configuration
----End

2.4.5 Setting the Authentication Method for the 802.1x User

Context
The authentication method for the 802.1x user can be set according to the actual networking
environment and security requirement.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
dot1x authentication-method { chap | eap | pap }
The authentication method is set for the 802.1x user.
By default, CHAP authentication is used for an 802.1x user. If you run the dot1x authentication-
method command repeatedly, the latest configuration takes effect.
l
l
l
PAP authentication and CHAP authentication are two kinds of termination authentication
methods and EAP authentication is a kind of relay authentication method.
If local authentication is adopted, you cannot use the EAP authentication for 802.1x users.
----End
2-12
If 802.1x authentication has been enabled, the authentication mode is changed from
802.1x authentication to MAC address bypass authentication on the interface after you
run the dot1x mac-bypass enable command.
To disable MAC address bypass authentication, run the undo dot1x command. Note that
802.1x functions are disabled.
The Password Authentication Protocol (PAP) uses the two-way handshake mechanism and
sends the password in plain text.
The Challenge Handshake Authentication Protocol (CHAP) uses the three-way handshake
mechanism. It transmits only the user name but not the password on the network; therefore,
compared with PAP authentication, CHAP authentication is more secure and reliable and
protects user privacy better.
In Extensible Authentication Protocol (EAP) authentication, the S9300 sends the
authentication information of an 802.1x user to the RADIUS server through EAP packets
without converting EAP packets into RADIUS packets. To use the PEAP, EAP-TLS, EAP-
TTLS, or EAP-MD5 authentication, you only need to enable the EAP authentication.
CAUTION
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents