Displaying And Maintaining 802.1X; 802.1X Authentication Configuration Examples; Basic 802.1X Authentication Configuration Example - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
8.
(Optional.) Configure the
maximum attempts for
retransmitting an
EAP-Request/Notification
packet to a client.

Displaying and maintaining 802.1X

Execute the display commands in any view and reset commands in user view.
Task
Display 802.1X session information,
statistics, or configuration information
of specified or all ports.
Display online 802.1X user information
(in standalone mode).
Display online 802.1X user information
(in IRF mode).
Clear 802.1X statistics.
Remove users from the 802.1X guest
VLAN on a port.

802.1X authentication configuration examples

Basic 802.1X authentication configuration example

Network requirements
As shown in
port GigabitEthernet 1/0/1. Implement MAC-based access control on the port, so the logoff of one
user does not affect other online 802.1X users.
Use RADIUS servers to perform authentication, authorization, and accounting for the 802.1X users.
If RADIUS authentication fails, perform local authentication on the access device.
Configure the host at 10.1.1.1/24 as the primary authentication and accounting servers, and the host
at 10.1.1.2/24 as the secondary authentication and accounting servers. Assign all users to the ISP
domain bbb.
Configure the shared key as name for packets between the access device and the authentication
server. Configure the shared key as money for packets between the access device and the
accounting server.
Command
dot1x smarton retry retries
Figure
36, the access device performs 802.1X authentication for users who connect to
Command
display dot1x [ sessions | statistics ] [ interface interface-type
interface-number ]
display dot1x connection [ interface interface-type
interface-number | slot slot-number | user-mac mac-addr |
user-name name-string ]
display dot1x connection [ chassis chassis-number slot
slot-number | interface interface-type interface-number |
user-mac mac-addr | user-name name-string ]
reset dot1x statistics [ interface interface-type
interface-number ]
reset dot1x guest-vlan interface interface-type
interface-number [ mac-address mac-address ]
100
Remarks
By default, the device allows a
maximum of 3 attempts for
retransmitting an
EAP-Request/Notification packet
to a client.

Advertisement

Table of Contents
loading

Table of Contents