Qtech QSW-3200-28FC Руководство пользователя онлайн [84/136] 481610

Qtech QSW-3200-28T Руководство пользователя онлайн [84/136] 481609
+7(495) 797-3311www.qtech.ru
Москва, Новозаводская ул., 18, стр. 1
73
other high level protocol. After using dot1x eap-transfer command, 802.1 authentication packet
encapsulated by EAP frame from user is sent to RADIUS server without any changes.
For example:
! Configure authentication packet tramsitting to be eap-finish
QTECH(config)#dot1x eap-finish
(4) Use dot1x re-authenticate command to re-authenticate current interface. Use dot1x re-
authentication command to enable 802.1x re-authentication. Use no dot1x re-authentication
command to disable 802.1x re-authentication. Use dot1x timeout re-authperiod command to
configure 802.1x re-authperiod. Use dot1x timeout re-authperiod interface command to
configure 802.1x re-authperiod of a specified interface. Please refer to command line
configuration to see the details.
(5) Use dot1x port-control command to configure port control mode.
After 802.1X authentication enables, all interfaces of the system default to be needing
authentication, but interfaces of uplink and connecting to server need not authentication. Use
dot1x port-control command to configure port control mode. Use no dot1x port-control
command to restore the default port control. Use show dot1x interface command to display
configuration of interface.
Configure it in interface configuration mode:
dot1x port-control { auto | forceauthorized | forceunauthorized }
For example:
! Ethernet 0/5 is RADIUS server port. Configure port-control mode of ethernet 0/5 to be
forceauthorized in interface configuration mode
QTECH(config-if-ethernet-0/5)#dot1x port-control forceauthorized
! Display 802.1X configuration of ethernet 0/5
QTECH(config)#show dot1x interface ethernet 0/5
port ctrlmode Reauth ReauthPeriod(s) MaxHosts
e0/5 forceauthorized disabled 3600 160
Total [26] item(s), printed [1] item(s).
(6) Use dot1x max-user command to configure the maximum number of supplicant systems an
ethernet port can accommodate. Use no dot1x max-user command to configure the maximum
number to be 1.
Configure it by using following command:
dot1x max-user user-num
For example:
! Configure the max-user of ethernet 0/5 is 10 in interface configuration mode
QTECH(config-if-ethernet-0/5)#dot1x max-user 10
(7) Use dot1x user cut command to remove specified online user.
Remove specified online user by specified username and MAC address.
For example:
! Remove user with username of aaa@qtech.ru
QTECH(config)#dot1x user cut username aaa@qtech.ru

Содержание

Похожие устройства

Скачать