H3C S5120-HI Security Configuration Manual page 76

Hide thumbs Also See for S5120-HI:
Table of Contents

Advertisement

# Configure bbb as the default ISP domain for all users. Then, if a user enters a username without
any ISP domain at login, the authentication and accounting methods of the default domain is used
for the user.
[Switch] domain default enable bbb
Configure 802.1X authentication:
3.
# Enable 802.1X globally.
[Switch] dot1x
# Enable 802.1X for port GigabitEthernet 1/0/1.
[Switch] interface gigabitethernet 1/0/1
[Switch-GigabitEthernet1/0/1] dot1x
[Switch-GigabitEthernet1/0/1] quit
# Configure the access control method. (Optional. The default setting meets the requirement.)
[Switch] dot1x port-method macbased interface gigabitethernet 1/0/1
Verifying the configuration
When you use H3C iNode client, no advanced authentication options are required, and the user can
pass authentication after entering username dot1x@bbb and the correct password in the client property
page.
If the 802.1X client of Windows XP is used, select the Enable IEEE 802.1X authentication for this network
option and select MD5-Challenge as the EAP type on the Authentication tab of the network connection
properties window. The user passes authentication after entering the correct username and password in
the pop-up authentication page.
After the user passes authentication, the server assigns the port connecting the client to VLAN 4.
Use the display connect command to view the connection information on the switch.
[Switch] display connection
Slot:
1
Index=22
IP=192.168.1.58
IPv6=N/A
MAC=0015-e9a6-7cfe
Total 1 connection(s) matched on slot 1.
Total 1 connection(s) matched.
# View the information of the specified connection on the switch.
[Switch] display connection ucibindex 22
Slot:
1
Index=22
IP=192.168.1.58
IPv6=N/A
MAC=0015-e9a6-7cfe
Access=8021X
Port Type=Ethernet,Port Name=GigabitEthernet1/0/1
Initial VLAN=2, Authorization VLAN=4
ACL Group=Disable
User Profile=N/A
CAR=Disable
Priority=Disable
Start=2011-04-26 19:41:12 ,Current=2011-04-26 19:41:25 ,Online=00h00m14s
, Username=dot1x@bbb
, Username=dot1x@bbb
,AuthMethod=CHAP
59

Advertisement

Table of Contents
loading

Table of Contents