Qtech QSW-3200-24T [83/136] 802 x configuration

Qtech QSW-3200-24T [83/136] 802 x configuration
+7(495) 797-3311www.qtech.ru
Москва, Новозаводская ул., 18, стр. 1
72
When the default domain name is disabled, switch will not deal with the invalid packet, if the
username goes without the domain name. After the default domain name is enabling, switch
will add @ and default domain name to a username wothout a domain name to authenticate.
To configure a default domain which must be existed, or the configuration fails.
For example:
! Configure default domain name to be QTECH.ru and enable the default domain
QTECH(config-aaa)#default domain-name enable QTECH.ru
(6) Use show domain command to display the configuration of the domain.
For example:
! Display the configuration of the domain
QTECH(config-aaa-QTECH.ru)#show domain
10.2.4 802.1X Configuration
Related command of 802.1X configuration is as following:
dot1x
dot1x daemon
dot1x eap-finish
dot1x eap-transfer
dot1x re-authenticate
dot1x re-authentication
dot1x timeout re-authperiod
dot1x timeout re-authperiod interface
dot1x port-control
dot1x max-user
dot1x user cut
(1) Use dot1x command to enable 802.1x. Domain and RADIUS server configurations can be
effective after this function enabling. Use no dot1x command to disable 802.1x. Use show
dot1x command to display 802.1x authentication information.
After enabling 802.1X, user accessed to system can access VLAN resources after
authentication. By default, 802.1X disables.
For example:
! Enable 802.1X
QTECH(config)#dot1x
! Display 802.1x authentication information
QTECH(config)#show dot1x
(2) When 802.1x enables, use this command to configure whether a port send 802.1x daemon
and sending period.
By default, 802.1x daemon is not sent by default. When 802.1x enables, default interval to
send daemon is 60seconds.
For example:
! Enable dot1x daemon on ethernet 0/5 with the period time of 20 seconds
QTECH(config-if-ethernet-0/5)#dot1x daemon time 20
(3) Use dot1x eap-finish and dot1x eap-transfer command to configure protocol type between
system and RADIUS server:
After using dot1x eap-transfer command, 802.1 authentication packet encapsulated by EAP
frame from user is sent to RADIUS server after transfering to data frame encapsulated by

Содержание

Скачать