Configuring Authentication Method For 802.1X User; Configuring Guest Vlan - H3C S9500 Series Operation Manual

Routing switches
Hide thumbs Also See for S9500 Series:
Table of Contents

Advertisement

Operation Manual – Security
H3C S9500 Series Routing Switches
Table 1-6 Set the Authentication in DHCP Environment
Disable the switch to trigger the user ID
authentication over the users who configure static
IP addresses in DHCP environment
Enable the switch to trigger the authentication over
them
By default, the switch can trigger the user ID authentication over the users who
configure static IP addresses in DHCP environment.

1.2.7 Configuring Authentication Method for 802.1x User

The following commands can be used to configure the authentication method for
802.1x user. Three kinds of methods are available: PAP authentication (RADIUS server
must support PAP authentication), CHAP authentication (RADIUS server must support
CHAP authentication), EAP relay authentication (switch send authentication
information to RADIUS server in the form of EAP packets directly and RADIUS server
must support EAP authentication).
Perform the following configuration in system view.
Table 1-7 Configure authentication method for 802.1x user
Configure authentication method for
802.1x user
Restore
method for 802.1x user
By default, CHAP authentication is used for 802.1x user authentication.

1.2.8 Configuring Guest VLAN

If Guest VLAN is enabled, a switch broadcasts active authentication packets to all
802.1x-enabled ports. The ports not sending response packets are added to Guest
VLAN when the maximum number of re-authentications is reached. Users in a Guest
VLAN can utilize resources in the Guest VLAN without undergoing the 802.1x
authentication, but they can utilize the resources outside the Guest VLAN only when
they have passed the 802.1x authentication. In this way, unauthenticated users can still
perform operations such as accessing some resources with the 802.1x client not
installed, and upgrading 802.1x client.
Perform the following configuration in system view or Ethernet interface view.
Operation
Operation
the
default
authentication
dot1x dhcp-launch
undo dot1x dhcp-launch
dot1x authentication-method { chap |
pap | eap md5-challenge}
undo dot1x authentication-method
1-7
Chapter 1 802.1x Configuration
Command
Command

Advertisement

Table of Contents
loading

This manual is also suitable for:

S9505S9508S9512

Table of Contents