Yamaha 10G SWR2310-28GT/18GT/10G Command Reference - Page 142

Set for forwarding control on an unauthenticated port for IEEE 802.1X authentication, 3.6 Set

Page 142 highlights

142 | Command Reference | Interface control [Note] This command can be specified only for both LAN/SFP port and logical interface. [Example] This command can be specified only for LAN/SFP port. SWR2310(config)#interface port1.1 SWR2310(config-if)#dot1x port-control auto 5.3.5 Set for forwarding control on an unauthenticated port for IEEE 802.1X authentication [Syntax] dot1x control-direction direction no dot1x control-direction [Parameter] direction : Sets the packet forwarding operation for unauthenticated ports Forwarding operation both in Description Both send and receive packets are discarded. Only receive packets are discarded. [Initial value] dot1x control-direction both [Input mode] interface mode [Description] Changes the packet forwarding operation for the applicable interface when the IEEE 802.1X authentication is unauthenticated. If this command is executed with the "no" syntax, the setting returns to the default. When "both" is specified, the packets received from the supplicant are discarded, and the broadcast/multicast packets to the interface to which the supplicant is connected from other ports are also discarded. When "in" is specified, only packets received from the supplicant are discarded, and the broadcast/multicast packets to the interface to which the supplicant is connected from other ports are forwarded. [Note] This command can be specified only for both LAN/SFP port and logical interface. If the host mode is set as multi-supplicant mode for the corresponding interface, or if it is used in conjunction with MAC authentication, the "in" setting is automatic. When the guest VLAN is configured using the applicable interface, the settings for this command will be disabled. Changing the settings for this command will make the authentication state return to the default. To use this command, you must enable the port authentication function for the applicable interface. (dot1x port-control command) [Example] Discard received packets only for the packet forwarding operation on an unauthenticated port of LAN port #1. SWR2310(config)#interface port1.1 SWR2310(config-if)#dot1x control-direction in 5.3.6 Set the EAPOL packet transmission count [Syntax] dot1x max-auth-req count no dot1x max-auth-req [Parameter] count : Maximum number of times EAPOL packets are transmitted

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278

[Note]
This command can be specified only for both LAN/SFP port and logical interface.
[Example]
This command can be specified only for LAN/SFP port.
SWR2310(config)#interface port1.1
SWR2310(config-if)#dot1x port-control auto
5.3.5 Set for forwarding control on an unauthenticated port for IEEE 802.1X authentication
[Syntax]
dot1x
control-direction
direction
no
dot1x
control-direction
[Parameter]
direction
:
Sets the packet forwarding operation for unauthenticated ports
Forwarding operation
Description
both
Both send and receive packets are discarded.
in
Only receive packets are discarded.
[Initial value]
dot1x control-direction both
[Input mode]
interface mode
[Description]
Changes the packet forwarding operation for the applicable interface when the IEEE 802.1X authentication is unauthenticated.
If this command is executed with the "no" syntax, the setting returns to the default.
When "both" is specified, the packets received from the supplicant are discarded, and the broadcast/multicast packets to the
interface to which the supplicant is connected from other ports are also discarded.
When "in" is specified, only packets received from the supplicant are discarded, and the broadcast/multicast packets to the
interface to which the supplicant is connected from other ports are forwarded.
[Note]
This command can be specified only for both LAN/SFP port and logical interface.
If the host mode is set as multi-supplicant mode for the corresponding interface, or if it is used in conjunction with MAC
authentication, the "in" setting is automatic.
When the guest VLAN is configured using the applicable interface, the settings for this command will be disabled.
Changing the settings for this command will make the authentication state return to the default.
To use this command, you must enable the port authentication function for the applicable interface. (
dot1x port-control
command)
[Example]
Discard received packets only for the packet forwarding operation on an unauthenticated port of LAN port #1.
SWR2310(config)#interface port1.1
SWR2310(config-if)#dot1x control-direction in
5.3.6 Set the EAPOL packet transmission count
[Syntax]
dot1x
max-auth-req
count
no
dot1x
max-auth-req
[Parameter]
count
:
<1-10>
Maximum number of times EAPOL packets are transmitted
142
| Command Reference | Interface control