Configuring The Ead Assistant Feature - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

If a username string contains none of the delimiters, the access device authenticates the user in the
mandatory or default ISP domain.
To specify a set of domain name delimiters:
Step
1.
Enter system view.
2.
Specify a set of domain
name delimiters for 802.1X
users.
NOTE:
If you configure the access device to send usernames with domain names to the RADIUS server,
make sure the domain delimiter can be recognized by the RADIUS server. For username format
configuration, see the user-name-format command in Security Command Reference.

Configuring the EAD assistant feature

When you configure the EAD assistant feature, follow these restrictions and guidelines:
You must disable MAC authentication and port security globally before you enable the EAD
assistant feature.
To make the EAD assistant feature take effect on an 802.1X-enabled port, you must set the port
authorization mode to auto.
When global MAC authentication or port security is enabled, the free IP does not take effect.
If you use free IP, guest VLAN, and Auth-Fail VLAN features together, make sure the free IP
segments are in both guest VLAN and Auth-Fail VLAN.
To allow a user to obtain a dynamic IP address before it passes 802.1X authentication, make
sure the DHCP server is on the free IP segment.
The server that provides the redirect URL must be on the free IP accessible to unauthenticated
users.
To avoid using up ACL resources when a large number of EAD users exist, you can shorten the
EAD rule timer.
To configure the EAD assistant feature:
Step
1.
Enter system view.
2.
Enable EAD assistant.
3.
Configure a free IP.
4.
(Optional.) Configure the
redirect URL.
5.
(Optional.) Set the EAD
rule timer.
Command
system-view
dot1x domain-delimiter string
Command
system-view
dot1x ead-assistant enable
dot1x ead-assistant free-ip
ip-address { mask-length |
mask-address }
dot1x ead-assistant url
url-string
dot1x timer ead-timeout
ead-timeout-value
92
Remarks
N/A
By default, only the at sign (@)
delimiter is supported.
Remarks
N/A
By default, this feature is disabled.
By default, no free IP is configured.
By default, no redirect URL is
configured.
Configure the redirect URL if users will
use Web browsers to access the
network.
The default setting is 30 minutes.

Advertisement

Table of Contents
loading

Table of Contents