H3C S6812 Series Command Reference Manual page 1775

Hide thumbs Also See for S6812 Series:
Table of Contents

Advertisement

[Sysname-Ten-GigabitEthernet1/0/1] dot1x
[Sysname-Ten-GigabitEthernet1/0/1] quit
Related commands
display dot1x
dot1x authentication-method
Use dot1x authentication-method to specify an EAP message handling method.
Use undo dot1x authentication-method to restore the default.
Syntax
dot1x authentication-method { chap | eap | pap }
undo dot1x authentication-method
Default
The access device performs EAP termination and uses CHAP to communicate with the RADIUS
server.
Views
System view
Predefined user roles
network-admin
Parameters
chap: Configures the access device to perform Extensible Authentication Protocol (EAP) termination
and use the Challenge Handshake Authentication Protocol (CHAP) to communicate with the
RADIUS server.
eap: Configures the access device to relay EAP packets, and supports any of the EAP
authentication methods to communicate with the RADIUS server.
pap: Configures the access device to perform EAP termination and use the Password Authentication
Protocol (PAP) to communicate with the RADIUS server.
Usage guidelines
The access device terminates or relays EAP packets.
In EAP termination mode—The access device re-encapsulates and sends the authentication
data from the client in standard RADIUS packets to the RADIUS server. The device performs
either CHAP or PAP authentication with the RADIUS server. In this mode the RADIUS server
supports only MD5-Challenge EAP authentication, and the username and password EAP
authentication initiated by an iNode client.
PAP transports usernames and passwords in plain text. The authentication method applies
to scenarios that do not require high security. To use PAP, the client can be an H3C iNode
802.1X client.
CHAP transports usernames in plain text and passwords in encrypted form over the
network. CHAP is more secure than PAP.
In EAP relay mode—The access device relays EAP messages between the client and the
RADIUS server. The EAP relay mode supports multiple EAP authentication methods, such as
MD5-Challenge, EAP-TLS, and PEAP. To use this mode, make sure the RADIUS server meets
the following requirements:
Supports the EAP-Message and Message-Authenticator attributes.
Uses the same EAP authentication method as the client.
7

Advertisement

Table of Contents
loading

This manual is also suitable for:

S6813 seriesS5150-ei

Table of Contents