No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

Configuration Guide - Security

CloudEngine 8800, 7800, 6800, and 5800 V200R005C10

This document describes the configurations of Security, including ACL, local attack defense, MFF, attack defense, traffic suppression and storm control, ARP security, Port security, DHCP snooping, ND snooping, PPPoE+, IPSG, SAVI, separating the management plane from the service plane, security risks.
Rate and give feedback :
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
(Optional) Configuring the Access Control Mode of an Interface

(Optional) Configuring the Access Control Mode of an Interface

Context

After 802.1x authentication is enabled, the device supports the following access control modes for an interface:
  • MAC address-based: All 802.1x authentication users on the interface must be authenticated. If any of the users goes offline, other users still maintain access to the network. This mode applies to individual users.
  • Interface-based: If one user on an interface has been authenticated successfully, other 802.1x authentication users on the same interface can access the network regardless of whether they are authenticated. However, after all authenticated users are disconnected, access of other unauthenticated users is rejected. This mode applies to group users.

This command can be configured in the system view or interface view. In the system view, the command can be configured on one or more interfaces; in the interface view, the command can only be configured on a specified interface.

Procedure

  • In the system view,

    1. Run system-view

      The system view is displayed.

    2. Run dot1x port-method { mac | port } interface interface-type { interface-number1 [ to interface-number2 ] } &<1-10>

      The access control mode for 802.1x authentication is configured.

      By default, access control for 802.1x authentication is performed based on MAC addresses.

    3. Run commit

      The configuration is committed.

  • In the interface view,

    1. Run system-view

      The system view is displayed.

    2. Run interface interface-type interface-number

      The interface view is displayed.

    3. Run dot1x port-method { mac | port }

      The access control mode for 802.1x authentication is configured.

      By default, access control for 802.1x authentication is performed based on MAC addresses.

    4. Run commit

      The configuration is committed.

Translation
Download
Updated: 2019-04-20

Document ID: EDOC1100074765

Views: 18649

Downloads: 63

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next