Enabling 802.1X; Configuration Guidelines; Configuration Procedure; Enabling Eap Relay Or Eap Termination - HP 6125G Configuration Manual

Security configuration guide
Hide thumbs Also See for 6125G:
Table of Contents

Advertisement

Enabling 802.1X

Configuration guidelines

If the PVID of a port is a voice VLAN, the 802.1X function cannot take effect on the port. For more
information about voice VLANs, see Layer 2
802.1X is mutually exclusive with link aggregation and service loopback group configuration on a
port.
Do not use the BPDU drop feature on an 802.1X-enabled port. The BPDU drop feature discards
802.1X packets arrived on the port.
On an 802.1X and MAC authentication enabled port, the EAP packet from an unknown MAC
address immediately triggers 802.1X authentication, and any other type of packet from an
unknown MAC address triggers MAC authentication 30 seconds after its arrival.

Configuration procedure

To enable 802.1X on a port:
Step
1.
Enter system view.
2.
Enable 802.1X globally.
3.
Enable 802.1X on a
port.

Enabling EAP relay or EAP termination

When you configure EAP relay or EAP termination, consider the following factors:
The support of the RADIUS server for EAP packets
The authentication methods supported by the 802.1X client and the RADIUS server
If the client is using only MD5-Challenge EAP authentication or the "username + password" EAP
authentication initiated by an HP iNode 802.1X client, you can use both EAP termination and EAP relay.
To use EAP-TL, PEAP, or any other EAP authentication methods, you must use EAP relay. When you make
your decision, see "A comparison of EAP relay and EAP termination" for help.
For more information about EAP relay and EAP termination, see "802.1X authentication procedures."
To configure EAP relay or EAP termination:
Step
1.
Enter system view.
LAN Switching Configuration Guide.
Command
system-view
dot1x
(Approach 1) In system view:
dot1x interface interface-list
(Approach 2) In Ethernet interface view:
a.
interface interface-type
interface-number
b.
dot1x
Command
system-view
80
Remarks
N/A
By default, 802.1X is
disabled globally.
Use either approach.
By default, 802.1X is
disabled on a port.
Remarks
N/A

Advertisement

Table of Contents
loading

This manual is also suitable for:

6125 blade switch series

Table of Contents