Configuring 802.1X Globally - H3C S9500E Series Security Configuration Manual

Routing switches
Hide thumbs Also See for S9500E Series:
Table of Contents

Advertisement

For remote RADIUS authentication, the username and password information must be
configured on the RADIUS server.
For local authentication, the username and password information must be configured on the
switch and the service type must be set to lan-access.
For configuration of the RADIUS client, see AAA in the Security Configuration Guide.

Configuring 802.1X globally

Follow these steps to configure 802.1X globally:
To do...
1.
Enter system view
2.
Enable 802.1X globally
3.
Specify the authentication
method
4.
Specify the port authorization
mode for specified or all ports
5.
Specify the port access control
method for specified or all
ports
6.
Set the maximum number of
users for specified or all ports
7.
Set the maximum number of
attempts to send an
authentication request to a
client
Use the command...
system-view
dot1x
dot1x authentication-method
{ chap | eap | pap }
dot1x port-control {
authorized-force | auto |
unauthorized-force } [
interface interface-list ]
dot1x port-method {
macbased | portbased } [
interface interface-list ]
dot1x max-user user-number [
interface interface-list ]
dot1x retry max-retry-value
76
Remarks
Required
Disabled by default
Optional
CHAP by default
Optional
auto by default
Optional
macbased by default
Optional
1024 by default
Optional
2 by default

Advertisement

Table of Contents
loading

Table of Contents