Configuring An 802.1X Port-Based Guest Vlan - HP 4800G Series Configuration Manual

24/48 port
Table of Contents

Advertisement

To do...
Enter system view
Enter Ethernet interface view
Set the port access control
mode for the port
Set the port access control
method for the port
Set the maximum number of
users for the port
Enable online user handshake
Enable multicast trigger
Specify the mandatory
authentication domain for the
port
Note that:
Enabling 802.1X on a port is mutually exclusive with adding the port to an aggregation group and
adding the port to a service loopback group.
In EAP relay authentication mode, the device encapsulates the 802.1X user information in the EAP
attributes of RADIUS packets and sends the packets to the RADIUS server for authentication. In
this case, you can configure the user-name-format command but it does not take effect. For
information about the user-name-format command, refer to AAA Commands in the Security
Volume.
If the username of a client contains the version number or one or more blank spaces, you can
neither retrieve information nor disconnect the client by using the username. However, you can use
items such as IP address and connection index number to do so.
Once enabled with the 802.1X multicast trigger function, a port sends multicast trigger messages to
the client periodically to initiate authentication.
For a user-side device sending untagged traffic, the voice VLAN function and 802.1X are mutually
exclusive and cannot be configured together on the same port. For details about voice VLAN, refer
to VLAN Configuration in the Access Volume.

Configuring an 802.1X Port-based Guest VLAN

Configuration prerequisites
Enable 802.1X.
Create the VLAN to be specified as the guest VLAN.
Set the port access control method to portbased.
Ensure that the 802.1X multicast trigger function is enabled.
Use the command...
system-view
interface interface-type
interface-number
dot1x port-control
{ authorized-force | auto |
unauthorized-force }
dot1x port-method
{ macbased | portbased }
dot1x max-user user-number
dot1x handshake
dot1x multicast-trigger
dot1x mandatory-domain
domain-name
1-14
Remarks
Optional
auto by default
Optional
macbased by default
Optional
256 by default
Optional
Enabled by default
Optional
Enabled by default
Optional
No mandatory authentication
domain is specified by default.

Advertisement

Chapters

Table of Contents
loading

Table of Contents