Dot1X Auth-Fail Vlan - HP A5500 EI Command Reference Manual

Hide thumbs Also See for A5500 EI:
Table of Contents

Advertisement

The network access device relays or terminates EAP packets:
In EAP termination mode, the access device re-encapsulates and sends the authentication data from
1.
the client in standard RADIUS packets to the RADIUS server, and performs either CHAP or PAP
authentication with the RADIUS server.
PAP transports usernames and passwords in clear text. The authentication method applies to
scenarios that do not require high security. To use PAP, the client must be an iNode 802.1X client.
CHAP transports username and encrypted password over the network. It is more secure than PAP. In
this mode the RADIUS server supports only MD5-Challenge.
In EAP relay mode, the access device relays EAP messages between the client and the RADIUS
2.
server. The EAP relay mode supports multiple EAP authentication methods, such as MD5-Challenge,
EAP-TL, and PEAP. To use this mode, you must ensure that the RADIUS server supports the EAP-
Message and Message-Authenticator attributes, and uses the same EAP authentication method as
the client. If this mode is used, the user-name-format command configured in RADIUS scheme view
does not take effect. For more information about the user-name-format command, see the chapter
―RADIUS configuration commands.‖
Local authentication supports PAP and CHAP.
If RADIUS authentication is used, you must configure the network access device to use the same
authentication method (PAP, CHAP, or EAP) as the RADIUS server.
Related commands: display dot1x.
Examples
# Enable the access device to terminate EAP packets and perform PAP authentication with the RADIUS
server.
<Sysname> system-view
[Sysname] dot1x authentication-method pap

dot1x auth-fail vlan

Syntax
dot1x auth-fail vlan authfail-vlan-id
undo dot1x auth-fail vlan
View
Layer 2 Ethernet interface view
Default level
2: System level
Parameters
authfail-vlan-id: Specifies the ID of the Auth-Fail VLAN for the port, in the range 1 to 4094. The VLAN
must already exist. Ensure that the VLAN has been created and is not a super VLAN. For more
information about super VLANs, see the Layer 2
EI Switch Series supports configuring super VLANs.
Descriptions
Use the dot1x auth-fail vlan command to configure an Auth-Fail VLAN for a port. An Auth-Fail VLAN
accommodates users that have failed 802.1X authentication because of the failure to comply with the
organization security strategy, such as using a wrong password.
LAN Switching Configuration Guide. Only the A5500
101

Advertisement

Table of Contents
loading

This manual is also suitable for:

A5500 si

Table of Contents