3Com SuperStack 4 Configuration Manual page 249

5500g-ei family
Hide thumbs Also See for SuperStack 4:
Table of Contents

Advertisement

Implementing 802.1x on
the Switch
Configuring 802.1x
The EAPoL-Start, EAPoL-Logoff and EAPoL-Key only exist between the user and
the Authenticator. The EAP-Packet information is re-encapsulated by the
Authenticator System and then transmitted to the Authentication Server System.
The EAPoL-Encapsulated-ASF-Alert is related to the network management
information and terminated by the Authenticator.
Although 802.1x provides user ID authentication, 802.1x itself is not enough to
implement the scheme. The administrator of the access device should configure
the AAA scheme by selecting RADIUS or local authentication to assist 802.1x to
implement the user ID authentication. For detailed description of AAA, refer to the
corresponding AAA configuration.
The Switch 5500G-EI Family not only supports the port access authentication
method regulated by 802.1x, but also extends and optimizes it in the following
way:
Support to connect several End Stations in the downstream via a physical port.
The access control (or the user authentication method) can be based on port or
MAC address.
In this way, the system becomes much securer and easier to manage.
The configuration tasks of 802.1x itself can be fulfilled in System View of the
Ethernet switch. When the global 802.1x is not enabled, you can configure the
802.1x state of the port. The configured items will take effect after the global
802.1x is enabled.
When 802.1x is enabled on a port, the maximum number of MAC address
learning which is configured by the command
cannot be configured on the port, and vice versa.
The main 802.1x configuration includes:
Enabling/disabling 802.1x
Setting the port access control mode
Setting the port access control method
Checking the users that log on the Switch via proxy
Setting the maximum number of users via each port
Setting the Authentication in DHCP Environment
Configuring the authentication method for 802.1x user
Setting the maximum times of authentication request message retransmission
Configuring timers
Enabling/disabling a quiet-period timer
Among the above tasks, the first one is compulsory, otherwise 802.1x will not take
any effect. The other tasks are optional. You can perform the configurations at
requirements.
Configuring 802.1x
mac-address max-mac-count
261

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Superstack 4 5500g-ei series

Table of Contents