No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

S600-E V200R013C00 Configuration Guide - User Access and Authentication

This document describes the configurations of User Access and Authentication Configuration, including AAA, NAC, and Policy Association.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
(Optional) Configuring the Access Control Mode of an Interface

(Optional) Configuring the Access Control Mode of an Interface

Context

After 802.1X authentication is enabled, the device supports two access control modes of an interface:
  • Interface-based mode: After the first user of the interface passes the authentication, other access users can access the network without being authenticated. However, when the authenticated user goes offline, other users can no longer access the network. The authentication scheme is applicable to group users.
  • MAC address-based mode: All users of the interface must be authenticated. When a user goes offline, other users can still access the network. The authentication mode is applicable to individual users.
NOTE:

When 802.1X authentication users are online, you cannot change the access control mode of an interface.

When MAC address-based access control is used in 802.1X authentication, ensure that the interface type is hybrid when you configure the authorization VLAN.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Configure the access control mode of an interface in the system or interface view.

    • In the system view:

    1. Run dot1x port-method { mac | port } interface { interface-type interface-number1 [ to interface-number2 ] } &<1-10>

      The access control mode of the interface is configured.

    • In the interface view:

    1. Run interface interface-type interface-number

      The interface view is displayed.

    2. Run dot1x port-method { mac | port }

      The access control mode of the interface is configured.

    By default, an interface uses the MAC address-based mode.

Translation
Download
Updated: 2019-04-20

Document ID: EDOC1100066170

Views: 20641

Downloads: 6

Average rating:
This Document Applies to these Products
Related Version
Related Documents
Share
Previous Next