Setting Up Port-Based Network Access Control; Setting 802.1X Switch Parameters; Enabling Mac Authentication For Non-Supplicants; Enabling 802.1X On Ports - Alcatel OmniSwitch 6600 Family Network Configuration Manual

Omniswitch 6600 series
Hide thumbs Also See for OmniSwitch 6600 Family:
Table of Contents

Advertisement

Setting Up Port-Based Network Access Control

Setting Up Port-Based Network Access Control
For port-based network access control, 802.1X must be enabled for the switch and the switch must know
which servers to use for authenticating 802.1X supplicants.
In addition, 802.1X must be enabled on each port that is connected to an 802.1X supplicant (or device).
Optional parameters may be set for each 802.1X port.
The following sections describe these procedures in detail.

Setting 802.1X Switch Parameters

Use the
aaa authentication 802.1x
tion server (or servers) to be used for authenticating 802.1X ports. The servers must already be configured
through the
aaa radius-server
ing all 802.1X ports on the switch:
-> aaa authentication 802.1x rad1 rad2
In this example, the rad1 server will be used for authenticating 802.1X ports. If rad1 becomes unavail-
able, the switch will use rad2 for 802.1X authentication. When this command is used, 802.1X is automati-
cally enabled for the switch.

Enabling MAC Authentication for Non-Supplicants

Use the
aaa authentication mac
authentication server (or servers) to be used for authenticating non-supplicants on 802.1x ports. As with
enabling 802.1x authentication, the servers specified with this command must already be configured
through the
aaa radius-server
The following example command specifies authentication servers for authenticating non-supplicant
devices on 802.1x ports:
-> aaa authentication mac rad1 rad2
Note that the same RADIUS servers can be used for 802.1x (supplicant) and MAC (non-supplicant)
authentication. Using different servers for each type of authentication is allowed but not required.
For more information about using MAC authentication and classifying non-supplicant devices, see
Access Guardian Policies" on page 22-8

Enabling 802.1X on Ports

To enable 802.1X on a port, use the
mobile port.
-> vlan port mobile 3/1
-> vlan port 3/1 802.1x enable
The vlan port 802.1x command enables 802.1X on port 1 of slot 3. The port will be set up with defaults
listed in
"802.1X Defaults" on page
To disable 802.1X on a port, use the disable option with vlan port 802.1x command. For more informa-
tion about vlan port commands, See
page 22-10
command to enable 802.1X for the switch and specify an authentica-
command. An example of specifying authentication servers for authenticat-
command to enable MAC authentication for the switch and specify an
command.
and
"Configuring Access Guardian Policies" on page
vlan port 802.1x
command. The port must also be configured as a
22-2.
Chapter 7, "Assigning Ports to VLANs."
OmniSwitch 6600 Family Network Configuration Guide
Configuring 802.1X
"Using
22-14.
April 2006

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents