Auth Two-Step Enable - Allied Telesis x510-28GTX Command Reference Manual

Stackable gigabit edge switches x510 series
Table of Contents

Advertisement

A
C
UTHENTICATION
OMMANDS
-
AUTH TWO
STEP ENABLE

auth two-step enable

Overview
This command enables a two-step authentication feature on an interface. When
this feature is enabled, the supplicant is authorized in a two-step process. If
authentication succeeds, the supplicant becomes authenticated. This command
will apply the two-step authentication method based on 802.1X-, MAC- or
Web-Authentication.
The no variant of this command disables the two-step authentication feature.
auth two-step enable
Syntax
no auth two-step enable
Default
Two step authentication is disabled by default.
Mode
Interface Configuration for a static channel, a dynamic (LACP) channel group, or a
switch port; or Authentication Profile mode.
Usage
The single step authentication methods (either user or device authentication) have
a potential security risk:
Two-step authentication solves this problem by authenticating both the user and
the device. The supplicant will only become authenticated if both these steps are
successful. If the first authentication step fails, then the second step is not started.
Examples
To enable the two step authentication feature, use the following commands:
awplus#
awplus(config)#
awplus(config-if)#
To disable the two step authentication feature, use the following commands:
awplus#
awplus(config)#
awplus(config-if)#
To enable MAC-Authentication followed by 802.1X-Authentication, use the
following commands:
awplus#
awplus(config)#
awplus(config-if)#
awplus(config-if)#
awplus(config-if)#
awplus(config-if)#
awplus(config-if)#
C613-50170-01 Rev B
an unauthorized user can access the network with an authorized device, or
an authorized user can access the network with an unauthorized device.
configure terminal
interface port1.0.2
auth two-step enable
configure terminal
interface port1.0.2
no auth two-step enable
configure terminal
interface port1.0.2
switchport mode access
auth-mac enable
dot1x port-control auto
auth dynamic-vlan-creation
auth two-step enable
Command Reference for x510 Series
AlliedWare Plus™ Operating System - Version 5.4.7-1.x
1756

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents