Introduction To 802.1X Configuration; Basic 802.1X Configuration; Configuration Prerequisites - 3Com E4500-24 Cli Configuration Manual

Hp e4500-24: user guide
Table of Contents

Advertisement

Note:
802.1x re-authentication will fail if a CAMS server is used and configured to perform authentication but
not accounting. This is because a CAMS server establishes a user session after it begins to perform
accounting. Therefore, to enable 802.1x re-authentication, do not configure the accounting none
command in the domain. This restriction does not apply to other types of servers.

Introduction to 802.1x Configuration

802.1x provides a solution for authenticating users. To implement this solution, you need to execute
802.1x-related commands. You also need to configure AAA schemes on switches and specify the
authentication scheme (RADIUS or local authentication scheme).
Figure 1-11 802.1x configuration
802.1x
802.1x
configuration
configuration
802.1x users use domain names to associate with the ISP domains configured on switches
Configure the AAA scheme (a local authentication scheme or a RADIUS scheme) to be adopted in
the ISP domain.
If you specify to use a local authentication scheme, you need to configure the user names and
passwords manually on the switch. Users can pass the authentication through 802.1x client if they
provide user names and passwords that match those configured on the switch.
If you specify to adopt the RADIUS scheme, the supplicant systems are authenticated by a remote
RADIUS server. In this case, you need to configure user names and passwords on the RADIUS
server and perform RADIUS client-related configuration on the switches.
You can also specify to adopt the RADIUS authentication scheme, with a local authentication
scheme as a backup. In this case, the local authentication scheme is adopted when the RADIUS
server fails.
Refer to the AAA Operation for detailed information about AAA scheme configuration.

Basic 802.1x Configuration

Configuration Prerequisites

Configure ISP domain and the AAA scheme to be adopted. You can specify a RADIUS scheme or
a local scheme.
Ensure that the service type is configured as lan-access (by using the service-type command) if
local authentication scheme is adopted.
ISP domain
ISP domain
AAA scheme
AAA scheme
configuration
configuration
1-13
Local
Local
authentication
authentication
RADIUS
RADIUS
scheme
scheme

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500

Table of Contents