Setting The Authentication Method For The 802.1X User - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
----End

2.4.5 Setting the Authentication Method for the 802.1x User

Context
The authentication method for the 802.1x user can be set according to the actual networking
environment and security requirement.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
dot1x authentication-method { chap | eap | pap }
The authentication method is set for the 802.1x user.
By default, CHAP authentication is used for an 802.1x user. If you run the dot1x authentication-
method command repeatedly, the latest configuration takes effect.
l The Password Authentication Protocol (PAP) uses the two-way handshake mechanism and
l The Challenge Handshake Authentication Protocol (CHAP) uses the three-way handshake
l In Extensible Authentication Protocol (EAP) authentication, the S3700 sends the
PAP authentication and CHAP authentication are two kinds of termination authentication
methods and EAP authentication is a kind of relay authentication method.
Issue 01 (2011-07-15)
After you run the dot1x mac-bypass command, the commands of enabling 802.1x
authentication on the interface are overwritten. The details are as follows:
– If 802.1x authentication is disabled on the interface, 802.1x authentication is enabled
after you run the dot1x mac-bypass command.
– If 802.1x authentication has been enabled, the authentication mode is changed from
802.1x authentication to MAC address bypass authentication on the interface after you
run the dot1x mac-bypass command.
To disable MAC address bypass authentication, run the undo dot1x enable command.
Note that 802.1x functions are disabled.
sends the password in plain text.
mechanism. It transmits only the user name but not the password on the network; therefore,
compared with PAP authentication, CHAP authentication is more secure and reliable and
protects user privacy better.
authentication information of an 802.1x user to the RADIUS server through EAP packets
without converting EAP packets into RADIUS packets. To use the PEAP, EAP-TLS, EAP-
TTLS, or EAP-MD5 authentication, you only need to enable the EAP authentication.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2 NAC Configuration
58

Advertisement

Table of Contents
loading

Table of Contents