Dot1X Auth-Fail Vlan - HP HSR6600 Command Reference Manual

Hide thumbs Also See for HSR6600:
Table of Contents

Advertisement

In EAP termination mode—The access device re-encapsulates and sends the authentication data
from the client in standard RADIUS packets to the RADIUS server, and performs either CHAP or PAP
authentication with the RADIUS server. In this mode the RADIUS server supports only
MD5-Challenge EAP authentication, and "username+password" EAP authentication initiated by an
iNode client.
PAP transports usernames and passwords in clear text. The authentication method applies to
scenarios that do not require high security. To use PAP, the client must be an HP iNode 802.1X
client.
CHAP transports username in plaintext and encrypted password over the network. It is more
secure than PAP.
In EAP relay mode—The access device relays EAP messages between the client and the RADIUS
server. The EAP relay mode supports multiple EAP authentication methods, such as MD5-Challenge,
EAP-TL, and PEAP. To use this mode, you must make sure that the RADIUS server supports the
EAP-Message and Message-Authenticator attributes and uses the same EAP authentication method
as the client. If this mode is used, the user-name-format command configured in RADIUS scheme
view does not take effect. For more information about the user-name-format command, see
"RADIUS configuration commands."
Local authentication supports PAP and CHAP.
If RADIUS authentication is used, you must configure the network access device to use the same
authentication method (PAP, CHAP, or EAP) as the RADIUS server.
Examples
# Enable the access device to terminate EAP packets and perform PAP authentication with the RADIUS
server.
<Sysname> system-view
[Sysname] dot1x authentication-method pap
Related commands
display dot1x

dot1x auth-fail vlan

Use dot1x auth-fail vlan to configure an Auth-Fail VLAN on a port for users that have failed 802.1X
authentication because of the failure to comply with the organization security strategy, such as using a
wrong password.
Use undo dot1x auth-fail vlan to restore the default.
Syntax
dot1x auth-fail vlan authfail-vlan-id
undo dot1x auth-fail vlan
Default
No Auth-Fail VLAN is configured on a port.
Views
Ethernet interface view
Default command level
2: System level
126

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hp 6600

Table of Contents