HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 92

Specifying an access control method, Setting the maximum number of concurrent 802.1X users on a port

Page 92 highlights

Specifying an access control method You can specify an access control method for one port in Ethernet interface view, or for multiple ports in system view. If different access control methods are specified for a port in system view and Ethernet interface view, the one specified later takes effect. To specify the access control method: Step 1. Enter system view. 2. Specify an access control method. Command system-view • (Approach 1) In system view: dot1x port-method { macbased | portbased } [ interface interface-list ] • (Approach 2) In Ethernet interface view: a. interface interface-type interface-number b. dot1x port-method { macbased | portbased } Remarks N/A Optional. Use either approach. By default, MAC-based access control applies. Setting the maximum number of concurrent 802.1X users on a port You can set the maximum number of concurrent 802.1X users for ports individually in Ethernet interface view or in bulk in system view. If different settings are configured for a port in both views, the setting configured later takes effect. To set the maximum number of concurrent 802.1X users on a port: Step 1. Enter system view. Command system-view • (Approach 1) In system view: dot1x max-user user-number [ interface 2. Set the maximum interface-list ] number of concurrent 802.1X users on a • (Approach 2) In Ethernet interface view: port. a. interface interface-type interface-number b. dot1x max-user user-number [ interface interface-list ] Remarks N/A Optional. Use either approach. The default maximum number of concurrent 802.1X users on a port is 2048. Setting the maximum number of authentication request attempts The network access device retransmits an authentication request if it receives no response to the request it has sent to the client within a period of time (specified by using the dot1x timer tx-period tx-period-value command or the dot1x timer supp-timeout supp-timeout-value command). The network 82

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

82
Specifying an access control method
You can specify an access control method for one port in Ethernet interface view, or for multiple ports in
system view. If different access control methods are specified for a port in system view and Ethernet
interface view, the one specified later takes effect.
To specify the access control method:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Specify an access
control method.
(Approach 1) In system view:
dot1x port-method
{
macbased
|
portbased
} [
interface
interface-list
]
(Approach 2) In Ethernet interface view:
a.
interface
interface-type
interface-number
b.
dot1x port-method
{
macbased
|
portbased
}
Optional.
Use either approach.
By default, MAC-based access
control applies.
Setting the maximum number of concurrent 802.1X
users on a port
You can set the maximum number of concurrent 802.1X users for ports individually in Ethernet interface
view or in bulk in system view. If different settings are configured for a port in both views, the setting
configured later takes effect.
To set the maximum number of concurrent 802.1X users on a port:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Set the maximum
number of concurrent
802.1X users on a
port.
(Approach 1) In system view:
dot1x
max-user
user-number
[
interface
interface-list
]
(Approach 2) In Ethernet interface view:
a.
interface
interface-type interface-number
b.
dot1x
max-user
user-number
[
interface
interface-list
]
Optional.
Use either approach.
The default maximum
number of concurrent
802.1X users on a port is
2048.
Setting the maximum number of authentication
request attempts
The network access device retransmits an authentication request if it receives no response to the request
it has sent to the client within a period of time (specified by using the
dot1x timer tx-period
tx-period-value
command or the
dot1x timer supp-timeout
supp-timeout-value
command). The network