HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 90
Enabling 802.1X, Configuration guidelines, Configuration procedure
View all HP 6125G manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 90 highlights
Enabling 802.1X Configuration guidelines • If the PVID of a port is a voice VLAN, the 802.1X function cannot take effect on the port. For more information about voice VLANs, see Layer 2-LAN Switching Configuration Guide. • 802.1X is mutually exclusive with link aggregation and service loopback group configuration on a port. • Do not use the BPDU drop feature on an 802.1X-enabled port. The BPDU drop feature discards 802.1X packets arrived on the port. • On an 802.1X and MAC authentication enabled port, the EAP packet from an unknown MAC address immediately triggers 802.1X authentication, and any other type of packet from an unknown MAC address triggers MAC authentication 30 seconds after its arrival. Configuration procedure To enable 802.1X on a port: Step 1. Enter system view. Command system-view 2. Enable 802.1X globally. dot1x 3. Enable 802.1X on a port. • (Approach 1) In system view: dot1x interface interface-list • (Approach 2) In Ethernet interface view: a. interface interface-type interface-number b. dot1x Remarks N/A By default, 802.1X is disabled globally. Use either approach. By default, 802.1X is disabled on a port. Enabling EAP relay or EAP termination When you configure EAP relay or EAP termination, consider the following factors: • The support of the RADIUS server for EAP packets • The authentication methods supported by the 802.1X client and the RADIUS server If the client is using only MD5-Challenge EAP authentication or the "username + password" EAP authentication initiated by an HP iNode 802.1X client, you can use both EAP termination and EAP relay. To use EAP-TL, PEAP, or any other EAP authentication methods, you must use EAP relay. When you make your decision, see "A comparison of EAP relay and EAP termination" for help. For more information about EAP relay and EAP termination, see "802.1X authentication procedures." To configure EAP relay or EAP termination: Step 1. Enter system view. Command system-view Remarks N/A 80