802.1X Non-Supplicant Allow-Eap - Alcatel-Lucent OmniSwitch 6850-48 Cli Reference Manual

Alcatel-lucent omniswitch 6850-48: reference guide
Hide thumbs Also See for OmniSwitch 6850-48:
Table of Contents

Advertisement

802.1X Commands

802.1x non-supplicant allow-eap

Configures whether or not the switch attempts subsequent 802.1x authentication for a device connected to
an 802.1x bypass-enabled port. When 802.1x bypass is enabled on the port, MAC authentication is
performed first on any device connected to that port. This command specifies the conditions under which
802.1x authentication is performed or bypassed after the initial MAC authentication process.
802.1x slot/port non-supplicant allow-eap {pass | fail | noauth | none}
Syntax Definitions
slot/port
pass
fail
noauth
none
Defaults
By default, only MAC authentication is applied to the supplicant device (802.1x classification is not
performed on the supplicant device).
Platforms Supported
OmniSwitch 6400, 6850, 6850E, 6855, 9000E
Usage Guidelines
The port specified with this command must also have 802.1x bypass enabled (see the
cant bypass
command). If bypass is not enabled, this command is not configurable and MAC authenti-
cation will not take precedence over 802.1x authentication.
Using this command with the none parameter is similar to setting the supplicant polling retry counter
to zero (see the
802.1x supp-polling retry
each command differs as follows:
>
When the supplicant polling retry is set to zero, EAP frames are ignored. MAC authentication is
only triggered when a non-EAP frame is received, which is when the supplicant times out and is in
an open state.
>
When the allow EAP is set to none, EAP frames are ignored but MAC authentication is triggered
when the first EAP frame is received and the supplicant is not in an open state.
When successful MAC authentication returns a VLAN ID or User Network Profile (UNP) and the
802.1x bypass operation is configured to initiate 802.1x authentication when a device passes MAC
authentication, the device is not moved into that VLAN or UNP. Instead, the device is moved into the
OmniSwitch CLI Reference Guide
The slot and port number of the 802.1x port.
Allows 802.1x (EAP frame) authentication if the supplicant passes
MAC authentication.
Allows 802.1x (EAP frame) authentication if the supplicant fails MAC
authentication.
Allows 802.1x (EAP frame) authentication if there is no MAC authenti-
cation configured on the port.
Prevents 802.1x authentication; only MAC authentication is performed
on any device accessing this port.
command). However, the functionality configured with
June 2012
802.1x suppli-
page 35-11

Advertisement

Table of Contents
loading

Table of Contents