ii
Configuring 802.1X ······················································································································································ 70
Configuration prerequisites ·································································································································· 70
802.1X configuration task list ······························································································································ 70
Enabling 802.1X ··················································································································································· 71
Specifying EAP relay or EAP termination ··········································································································· 72
Setting the port authorization state ······················································································································ 72
Specifying an access control method ·················································································································· 73
Setting the maximum number of concurrent 802.1X users on a port ······························································ 73
Setting the maximum number of authentication request attempts ···································································· 74
Setting the 802.1X authentication timeout timers ······························································································ 74
Configuring the online user handshake function································································································ 75
Configuring the authentication trigger function ································································································· 76
Specifying a mandatory authentication domain on a port ··············································································· 76
Enabling the quiet timer ········································································································································ 77
Enabling the periodic online user re-authentication function ············································································ 77
Configuring an 802.1X guest VLAN ··················································································································· 78
Configuring an Auth-Fail VLAN ··························································································································· 79
Configuring an 802.1X critical VLAN ················································································································ 80
Specifying supported domain name delimiters ·································································································· 81
Displaying and maintaining 802.1X ··························································································································· 81
802.1X configuration examples ··································································································································· 82
802.1X authentication configuration example ·································································································· 82
802.1X with guest VLAN and VLAN assignment configuration example ······················································· 84
802.1X with ACL assignment configuration example ······················································································· 87
EAD fast deployment configuration ·························································································································· 89
EAD fast deployment overview ····································································································································· 89
EAD fast deployment implementation ················································································································· 89
Configuring EAD fast deployment ································································································································ 89
Configuration prerequisites ·································································································································· 89
Configuration procedure ······································································································································ 90
Displaying and maintaining EAD fast deployment ····································································································· 91
EAD fast deployment configuration example ·············································································································· 91
Troubleshooting EAD fast deployment ························································································································· 93
Web browser users cannot be correctly redirected ·························································································· 93
MAC authentication configuration ···························································································································· 95
MAC authentication overview ······································································································································ 95
User account policies ············································································································································ 95
Authentication approaches ·································································································································· 95
MAC authentication timers ··································································································································· 96
Using MAC authentication with other features ··········································································································· 96
VLAN assignment ·················································································································································· 96
ACL assignment ····················································································································································· 97
Guest VLAN ··························································································································································· 97
Critical VLAN ························································································································································· 97
MAC authentication configuration task list ················································································································· 97
Basic configuration for MAC authentication ··············································································································· 98
Configuration prerequisites ·································································································································· 98
Configuration procedure ······································································································································ 98
Specifying an authentication domain for MAC authentication users ······································································· 99
Configuring a MAC authentication guest VLAN ······································································································ 100
Configuration prerequisites ································································································································ 100
Configuration procedure ···································································································································· 100
Configuring a MAC authentication critical VLAN ···································································································· 101