Operation Manual - Security
Quidway S3000-EI Series Ethernet Switches Chapter 1
802.1x Configuration
Huawei Technologies Proprietary
1-5
By default, the m x performing access control o uto (automatic
identification mode, which is also called prot
o ermits P
does not permit the user to access the netw ntication flow is
p h
th sources. This is the most com
1.2.3 Setting the Port Access Control Method
Table 1-3 Setting the port access control method
ode of 802.1 n the port is a
ocol control mode). That is, the initial state
EA oL packets receiving/transmitting and
ork resources. If the authe
f the port is unauthorized. It only p
assed, the port will be switched to the aut
e network re
orized state and permit the user to access
mon case.
The following commands are used for setting 802.1x access control method on the
specified port. When no port is specified in system view, the access control method of
port is configured globally.
Perform the following configurations in system view or Ethernet port view.
Operation Command
Set port access control method
portbased } [ interface interface-list ]
dot1x port-method { macbased |
Restore the default port access control
method
undo dot1x port-method [ interface
interface-list ]
By default, 802.1x authentication method on th
authentication is performed based on MAC addresse
e port is macbased. That is,
s.
1.2.4 Checking the Users that Log on the Sw
The following commands are used for chec r
p
ollowing configurations in system view or Ethernet port view.
itch via Proxy
king the use s that log on the switch via
roxy.
Perform the f
Table 1-4 Checking the users that log on the switch via proxy
Operation Command
Enable the check for access users via dot1x supp-proxy-check { logoff |
erface-list ]
proxy
trap } [ interface int
Cancel the check for access users via
undo dot1x supp-proxy-check
proxy
{ logoff | trap } [ interface interface-list ]
These commands can be used to set on the specified interface when executed in
system view. The parameter interface-list cannot be input when the command is
executed in Ethernet Port view and it has effect only on the current interface. After