Operation Manual ā 802.1x 
Quidway S3900 Series Ethernet Switches-Release 1510  Chapter 1  802.1x Configuration
 
Huawei Technologies Proprietary 
1-13 
z  If you specify to use the RADIUS scheme, that is to say the supplicant systems are 
authenticated by a remote RADIUS server, you need to configure the related user 
names and passwords on the RADIUS server and perform RADIUS client-related 
configuration on the switches. 
z  If you specify to adopt a local authentication scheme, you need to configure user 
names and passwords manually on the switches. Users can pass the 
authentication through 802.1x client if they provide the user names and passwords 
that match with those stored in the switches. 
z  You can also specify to adopt RADIUS authentication scheme, with a local 
authentication scheme as a backup. In this case, the local authentication scheme 
is adopted when the RADIUS server fails. 
Refer to the AAA&RADIUS&RADIUS&HWTACACS&EAD Operation Manual for 
detailed information about AAA configuration. 
1.3  Basic 802.1x Configuration 
To utilize 802.1x features, you need to perform basic 802.1x configuration. 
1.3.1  Prerequisites 
z  Configure ISP domain and its AAA scheme, specify the authentication scheme 
( RADIUS or a local scheme) . 
z  Ensure that the service type is configured as lan-access (by using the 
service-type command) for local authentication scheme. 
1.3.2  Configuring Basic 802.1x Functions 
Table 1-1 Configure basic 802.1x functions 
Operation  Command  Description 
Enter system view 
system-view 
ā 
Enable 802.1x 
globally 
dot1x 
Required 
By default, 802.1x is disabled 
globally. 
Use the following command 
in system view: 
dot1x [ interface 
interface-list ] 
Enable 802.1x for  
specified ports
 
Use the following command 
in port view: 
dot1x 
Required 
By default, 802.1x is disabled 
for all ports.