Configuring 802.1X; Configuration Prerequisites; Configuring 802.1X Globally - HP 4800G Series Configuration Manual

24/48 port
Table of Contents

Advertisement

authentication domain for authentication, authorization, and accounting of all 802.1X users on the port.
In this way, users accessing the port cannot use any account in other domains.
Meanwhile, for EAP relay mode 802.1X authentication that uses certificates, the certificate of a user
determines the authentication domain of the user. However, you can specify different mandatory
authentication domains for different ports even if the user certificates are from the same certificate
authority (that is, the user domain names are the same). This allows you to deploy 802.1X access
policies flexibly.

Configuring 802.1X

Configuration Prerequisites

802.1X provides a user identity authentication scheme. However, 802.1X cannot implement the
authentication scheme solely by itself. RADIUS or local authentication must be configured to work with
802.1X.
Configure the ISP domain to which the 802.1X user belongs and the AAA scheme to be used (that
is, local authentication or RADIUS).
For remote RADIUS authentication, the username and password information must be configured
on the RADIUS server.
For local authentication, the username and password information must be configured on the device
and the service type must be set to lan-access.
For detailed configuration of the RADIUS client, refer to AAA Configuration in the Security Volume.

Configuring 802.1X Globally

Follow these steps to configure 802.1X globally:
To do...
Enter system view
Enable 802.1X globally
Set the authentication method
Set the port
access control
parameters
Use the command...
system-view
dot1x
dot1x authentication-method
{ chap | eap | pap }
Set the port
dot1x port-control
access control
{ authorized-force | auto |
mode for
unauthorized-force }
specified or all
[ interface interface-list ]
ports
Set the port
access control
dot1x port-method
method for
{ macbased | portbased }
specified or all
[ interface interface-list ]
ports
Set the
maximum
number of
dot1x max-user user-number
users for
[ interface interface-list ]
specified or all
ports
1-12
Remarks
Required
Disabled by default
Optional
CHAP by default
Optional
auto by default
Optional
macbased by default
Optional
256 by default

Advertisement

Chapters

Table of Contents
loading

Table of Contents