80
Configuration prerequisites
• Configure an ISP domain and AAA scheme (local or RADIUS authentication) for 802.1X users.
• If RADIUS authentication is used, create user accounts on the RADIUS server.
• If local authentication is used, create local user accounts on the access device and set the service
type to lan-access.
802.1X configuration task list
Task Remarks
Enabling 802.1X Required
Enabling EAP relay or EAP termination Optional
Setting the port authorization state Optional
Specifying an access control method Optional
Setting the maximum number of concurrent 802.1X users on a port Optional
Setting the maximum number of authentication request attempts Optional
Setting the 802.1X authentication timeout timers Optional
Configuring the online user handshake function Optional
Configuring the authentication trigger function Optional
Specifying a mandatory authentication domain on a port Optional
Configuring the quiet timer Optional
Enabling the periodic online user re-authentication function Optional
Configuring a port to send EAPOL frames untagged Optional
Setting the maximum number of 802.1X authentication attempts for MAC
authentication users
Optional
Configuring a VLAN group Optional
Configuring an 802.1X guest VLAN Optional
Configuring an 802.1X Auth-Fail VLAN Optional
Configuring an 802.1X critical VLAN Optional
Specifying supported domain name delimiters Optional
Configuring an 802.1X voice VLAN Optional
Configuring 802.1X MAC address binding Optional