3Com 4500G Family Configuration Manual page 614

24/48 port
Hide thumbs Also See for 4500G Family:
Table of Contents

Advertisement

To do...
Enter system view
In system view
Enable 802.1X
for one or more
In Ethernet
ports
interface view
Configuring 802.1X parameters for a port
Follow these steps to configure 802.1X parameters for a port:
To do...
Enter system view
Enter Ethernet interface view
Set the port access control mode
for the port
Set the port access control method
for the port
Set the maximum number of users
for the port
Enable online user handshake
Enable the online handshake
security function
Enable multicast trigger
Enable periodic re-authentication
Specify the mandatory
authentication domain for the port
Note that:
Enabling 802.1X on a port is mutually exclusive with adding the port to an aggregation group.
In EAP relay authentication mode, the device encapsulates the 802.1X user information in the EAP
attributes of RADIUS packets and sends the packets to the RADIUS server for authentication. In
this case, you can configure the user-name-format command but it does not take effect. For
information about the user-name-format command, refer to AAA Commands in the Security
Volume.
If the username of a client contains the version number or one or more blank spaces, you can
neither retrieve information nor disconnect the client by using the username. However, you can use
items such as IP address and connection index number to do so.
The online user handshake security function is implemented based on the online user handshake
function. To bring the security function into effect, keep the online user handshake function
enabled.
Use the command...
system-view
dot1x interface interface-list
interface interface-type interface-number
dot1x
Use the command...
system-view
interface interface-type
interface-number
dot1x port-control
{ authorized-force | auto |
unauthorized-force }
dot1x port-method { macbased |
portbased }
dot1x max-user user-number
dot1x handshake
dot1x handshake secure
dot1x multicast-trigger
dot1x re-authenticate
dot1x mandatory-domain
domain-name
1-13
Remarks
Required
Use either approach.
Disabled by default
Remarks
Optional
auto by default
Optional
macbased by default
Optional
256 by default
Optional
Enabled by default
Optional
Disabled by default
Optional
Enabled by default
Required
Disabled by default
Optional
No mandatory authentication
domain is specified by default.

Hide quick links:

Advertisement

Chapters

Table of Contents
loading

Table of Contents