Dot1X Mandatory-Domain - H3C S5120-SI Series Command Reference Manual

Hide thumbs Also See for S5120-SI Series:
Table of Contents

Advertisement

Examples
# Enable online user handshake.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/4
[Sysname-GigabitEthernet1/0/4] dot1x handshake

dot1x mandatory-domain

Syntax
dot1x mandatory-domain domain-name
undo dot1x mandatory-domain
View
Ethernet Interface view
Default Level
2: System level
Parameters
domain-name: ISP domain name, a case-insensitive string of 1 to 24 characters.
Description
Use the dot1x mandatory-domain command to specify the mandatory authentication domain for
users accessing the port.
Use the undo dot1x mandatory-domain command to remove the mandatory authentication domain.
By default, no mandatory authentication domain is specified.
Note that:
When authenticating an 802.1X user trying to access the port, the system selects an authentication
domain in the following order: the mandatory domain, the ISP domain specified in the username,
and the default ISP domain.
The specified mandatory authentication domain must exist.
On a port configured with a mandatory authentication domain, the user domain name displayed by
the display connection command is the name of the mandatory authentication domain. For
detailed information about the display connection command, refer to AAA Commands.
Related commands: display dot1x.
Examples
# Configure the mandatory authentication domain my-domain for 802.1X users on GigabitEthernet
1/0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] dot1x mandatory-domain my-domain
# After 802.1X user usera passes the authentication, execute the display connection command to
display the user connection information on GigabitEthernet 1/0/1.
1-9

Advertisement

Table of Contents
loading

Table of Contents