Chapter 2 Habp Configuration; Introduction To Habp; Habp Server Configuration - H3C S3600 Series Operation Manual

Hide thumbs Also See for S3600 Series:
Table of Contents

Advertisement

Operation Manual – 802.1x
H3C S3600 Series Ethernet Switches-Release 1510

Chapter 2 HABP Configuration

2.1 Introduction to HABP

With 802.1x enabled, a switch authenticates and then authorizes 802.1x-enabled ports.
Packets can be forwarded only by authorized ports. For ports connected to the switch
and are not authenticated and authorized by 802.1x, their received packets will be
filtered. This means that users cannot manage the attached switches. Huawei
authentication bypass protocol (HABP) is designed to address this problem.
An HABP packet carries the MAC addresses of the attached switches with it. It can
bypass the 802.1x authentications when traveling between HABP-enabled switches,
through which management devices can obtain the MAC addresses of the attached
switches and thus the management of the attached switches is feasible.
HABP is implemented by HABP server and HABP client. Normally, an HABP server
sends HABP request packets regularly to HABP clients to collect the MAC addresses of
the attached switches. HABP clients respond to the HABP request packets and forward
the HABP request packets to lower-level switches. HABP servers usually reside on
management devices and HABP clients usually on attached switches.
For ease of switch management, it is recommended that you enable HABP for
802.1x-enabled switches.

2.2 HABP Server Configuration

With the HABP server launched, a management device sends HABP request packets
regularly to the attached switches to collect their MAC addresses. You need also to
configure the interval on the management device for an HABP server to send HABP
request packets.
Table 2-1 Configure an HABP server
Operation
Enter system view
Enable HABP
Configure
current switch to
be an HABP server
Command
system-view
habp enable
the
habp server vlan
vlan-id
2-1
Chapter 2 HABP Configuration
Description
Required
HABP is enabled by default.
Required
By default, a switch operates as an
HABP client after you enable HABP on
the switch. If you want to use the switch
as a management switch, you need to
configure the switch to be an HABP
server.

Advertisement

Table of Contents
loading

Table of Contents