Dell 5324 manual Dot1x re-authentication, Console config-if#dot1x port-control auto, 373

Page 373

Default Configuration

force-authorized

Command Mode

Interface configuration (Ethernet)

User Guidelines

It is recommended to disable spanning tree or to enable spanning-tree PortFast mode on 802.1x edge ports (ports in auto state that are connected to end stations), in order to get immediately to the forwarding state after successful authentication.

Examples

The following example enables 802.1X authentication on the interface.

Console (config)# interface ethernet g8

Console (config-if)#dot1x port-control auto

dot1x re-authentication

The dot1x re-authenticationInterface Configuration mode command enables periodic re- authentication of the client. Use the no form of this command to return to the default setting.

Syntax

dot1x re-authentication

no dot1x re-authentication

This command has no arguments or keywords.

Default Configuration

Periodic re-authentication is disabled.

Command Mode

Interface configuration (Ethernet)

User Guidelines

It is recommended to use re-authentication because if re-authentication is not defined, once a port is authenticated, it will remain in this state until the port is down or a log-off message is sent by client.

802.1x Commands

373

Image 373
Contents CLI Reference Guide Aug Contents Using the CLI Address Table Commands Clock Ethernet Configuration Commands Igmp Snooping Commands Lacp Commands Management ACL Port Monitor Commands Rmon Commands Spanning-Tree Commands SSH Commands Syslog Commands Tacacs Commands Vlan Commands 32 802.1x Commands 382 Page Command Groups Command GroupsIntroduction Configures Tacacs commands Configures and reports on Spanning Tree protocolConfigures commands related to 802.1x security protocol Address Table Commands AAA CommandsConfigures the system to automatically switch Configures an external time source forDefines an authentication key for Simple Displays statically created entries in the bridgeConfiguration and Image Files Commands Displays the backup configuration file contents Ethernet Configuration CommandsGvrp Commands Defines a default gateway router Igmp Snooping CommandsIP Addressing Sets an IP addressDeletes entries from the host name-to-address Line CommandsCache Sets the line for automatic baud rate detection Lldp CommandsPHY Diagnostics Commands Management ACL CommandsPort Monitor Commands Port Channel CommandsQoS Commands Enables each port trust state Radius CommandsSnmp Commands Rmon CommandsSpanning Tree Commands MST Overrides the default link-type setting SSH CommandsSets the default path cost method Syslog Commands Tacacs Commands System Management CommandsReloads the operating system Vlan Commands User Interface CommandsSwitches the mode to debug Disables the default Vlan functionalityInterface Reserves a Vlan as the internal usage Vlan of anWeb Server Commands Command Description Access Mode 802.1x CommandsCommand Groups GC Global Configuration Mode Command ModesDevice Notification operation Sntp IC Interface Configuration ModeFrame, from the client, before resending the request An Extensible Authentication Protocol EAP request/identityReserves a Vlan as the internal usage Vlan of an interface Enables the Simple Network Time Protocol Sntp client on an LC Line Configuration ModeCommand Description PE Privileged User Exec Mode MA Management Access-level ModeVlan UE User Exec Mode SP SSH Public Key ModeCommand Modes VC Vlan Configuration Mode W . d e l l . c o m s u p p o r t . d e l l . c o m CLI Command Modes Using the CLIIntroduction Privileged Exec Mode User Exec ModeExit End Ctrl+Z Global Configuration ModeStarting the CLI Entering Commands Editing FeaturesConsoleconfig# username admin password smith Negating the Effect of Commands Terminal Command BufferCommand Completion Config#interface ethernetKeyboard Shortcuts CLI Command ConventionsItalic font EnterUsing the CLI Aaa authentication login AAA CommandsDefault Configuration Command ModeFollowing example configures authentication login Aaa authentication enableExample Console config# aaa authentication enable default enable Login authenticationConsole config-line#login authentication default Enable authenticationConsole config-line#enable authentication default Ip http authenticationFollowing example configures the http authentication Show authentication methods Ip https authenticationFollowing example configures https authentication This command has no default configuration Syntax Show authentication methods Default ConfigurationPrivileged Exec mode Following example displays the authentication configurationConsole# show authentication methods PasswordSyntax Password password encrypted No password No password is required Enable passwordFollowing example specifies a password secret on a line Show users accounts UsernameNo user is defined Console# show users accounts Syntax Show users accounts Default ConfigurationAAA Commands Interface configuration Vlan mode Address Table CommandsBridge address This example, bridge multicast filtering is enabled Disabled. All multicast addresses are flooded to all portsConsole config# bridge multicast filtering Bridge multicast filteringExamples No multicast addresses are definedFollowing example registers the MAC address Bridge multicast forbidden address Command ModesNo forbidden addresses are defined Bridge multicast forward-all Disable forward-all on the specified interfaceBridge multicast forbidden forward-all This example all multicast packets on port g8 are forwardedSyntax Bridge aging-timeSyntax Clear bridge Clear bridgeConsole# clear bridge Interface Configuration Ethernet, port-channel mode Disabled No port securityPort security Port security routed secure-address Console config-if#port security routed secure-addressShow bridge address-table Mac-address-Specify a MAC address in the formatPort-channel-number-A valid port-channel number Console# show bridge address-table Show bridge address-table staticConsole# show bridge address-table static Show bridge address-table countSyntax Show bridge address-table count vlan vlan Vlan -Specific VlanConsole# show bridge address-table count Show bridge multicast address-tableConsole # show bridge multicast address-table format ip Console # show bridge multicast address-tableShow ports security Show bridge multicast filteringSyntax Show bridge multicast filtering vlan-id Vlanid-A valid Vlan ID valueConsole # show ports security Clock set ClockClock source Syntax Clock source sntp No clock sourceNo external clock source Clock timezoneConsole# clock source sntp Clock summer-time No authentication key is defined Sntp authentication-keyConsoleconfig# sntp authentication-key 8 md5 ClkKey Sntp authenticateSyntax Sntp authenticate No sntp authenticate Following example authenticates key Sntp client poll timerSntp trusted-key Not trustedConsole config# sntp client poll timer Sntp broadcast client enableConsole config# sntp broadcast client enable Sntp client enable interface Sntp anycast client enableConsole config-if#sntp anycast client enable Syntax Sntp client enable No sntp client enableConsole config# sntp unicast client enable Sntp unicast client enable101 Sntp unicast client poll Console config# sntp unicast client pollSntp server Syntax Sntp unicast client poll no sntp unicast client pollSyntax Show clock detail Show clock103 104 Console# show clockSyntax Show sntp configuration Show sntp configurationConsole# show sntp configuration 105Syntax Show sntp status Show sntp statusFollowing example shows the status of the Sntp 106107 Clock Delete startup-config Configuration and Image FilesConsole# delete startup-config Copy110 Understanding Invalid Combinations of Source and DestinationCopy Character Descriptions Storing the Running or Startup Configuration on a ServerCopying image file from a Server to Flash Memory 111Syntax Boot system image-1 image-2 Boot systemConsole# boot system image-1 112Syntax Show running-config sort type Show running-configSort type defaults to interface if unspecified 113Console# show running-config no spanning-tree Show startup-configSyntax Show startup-config sort type 114 115 Console# show startup-config no spanning-tree Show backup-configSyntax Show backup-config 116 117 Console# show backup-config software versionSyntax Show bootvar Default Configuration Show bootvarConsole# show bootvar 118Interface ethernet Ethernet Configuration CommandsInterface range ethernet Interface is enabled Syntax Shutdown No shutdown Default ConfigurationFollowing example disables port g5 ShutdownSpeed DescriptionSyntax Description string No description Syntax Speed 100 1000 No speedSyntax Duplex half full No duplex Duplex122 Syntax Negotiation No negotiation Default Configuration Consoleconfig# interface ethernet g5Negotiation FlowcontrolSyntax Flowcontrol auto on off No flowcontrol MdixSyntax Mdix on auto No mdix 124Back-pressure Syntax Back-pressure No back-pressure Default Configuration125 Clear counters Port jumbo-frame126 Set interface active Show interfaces configurationConsole# clear counters ethernet g1 Console# set interface active ethernet g5128 Interfaces configuration129 Show interfaces statusConsole# show interfaces status 130131 Show interfaces descriptionConsole# show interfaces description ethernet g1 Show interfaces counters132 Console# show interfaces counters 133Console# show interfaces counters ethernet g1 Following example displays counters for port g1Following table describes the fields shown in the display 134Ieee Std .3, 2000 Edition, section 135Show ports jumbo-frame Syntax Show ports jumbo-frame Default Configuration136 Consoleconfig# port storm-control include-multicast Port storm-control broadcast enablePort storm-control include-multicast Console# show ports jumbo-frameConsoleconfig-if#port storm-control broadcast enable Broadcast storm control is disabledDefault storm control broadcast rate is Port storm-control broadcast rateFollowing example displays the storm control configuration Consoleconfig-if#port storm-control broadcast rateShow ports storm-control Syntax Show ports storm-control interface140 Gvrp enable global Gvrp CommandsGvrp enable interface Syntax Gvrp enable No gvrp enable Default ConfigurationFollowing example enables Gvrp on ethernet g8 Garp timer142 Gvrp vlan-creation-forbid By default, dynamic Vlan creation is enabled143 Console config-if#gvrp registration-forbid Console config-if#gvrp vlan-creation-forbidGvrp registration-forbid Clear gvrp statisticsConsole# clear gvrp statistics ethernet g8 Show gvrp configuration145 Show gvrp statistics Console# show gvrp configuration146 Following example shows Gvrp statistics information Show gvrp error-statistics147 Console# show gvrp statisticsFollowing example displays Gvrp statistics information Console# show gvrp-error statistics148 Ip igmp snooping Global Igmp Snooping CommandsIp igmp snooping Interface 149Ip igmp snooping host-time-out Ip igmp snooping mrouter150 Ip igmp snooping mrouter-time-out Console config-if#ip igmp snooping host-time-out151 Default leave-time-out configuration is 10 seconds Console config-if#ip igmp snooping mrouter-time-outConsole config-if#ip igmp snooping leave-time-out Ip igmp snooping leave-time-outShow ip igmp snooping interface Show ip igmp snooping mrouterConsole # show ip igmp snooping mrouter Example displays Igmp snooping information Show ip igmp snooping groupsConsole # show ip igmp snooping interface 154Console # show ip igmp snooping groups Example shows Igmp snooping information155 Igmp Snooping Commands Clear host dhcp IP Addressing CommandsIp address Console# clear host dhcpIp address dhcp Interface configuration Ethernet, VLAN, port-channelNo IP address is defined for interfaces 158Syntax Ip default-gateway ip-address No ip default-gateway Ip default-gatewayNo default gateway is defined 159Show ip interface Following example defines an ip default gateway160 Console# show ip interface Arp161 Console config# arp 198.133.219.232 00000c400fbc ethernet Arp timeoutClear arp-cache Show arp Syntax Show arp Default ConfigurationConsole# clear arp-cache Following example displays entries in the ARP tableIp domain-name Ip domain-lookupSyntax Ip domain-lookup No ip domain-lookup Syntax Ip domain-name name No ip domain-nameIp host Ip name-serverNo name server addresses are specified Following example sets the available name serverSyntax Ip host name address No ip host name Clear hostNo host is defined Syntax Clear host nameShow hosts Default Configuration Command ModeSyntax Show hosts name 167168 Lacp system-priority Lacp CommandsLacp port-priority Syntax Lacp port-priority value No lacp port-prioritySyntax Lacp timeout long short No lacp timeout Lacp timeoutDefault port timeout value is long 170Show lacp port-channel Show lacp ethernetConsole# show lacp ethernet g1 statistics Syntax Show lacp port-channel portchannelnumber172 Console# show lacp port-channelLine Line CommandsSyntax Line console telnet ssh Syntax Speed bpsSyntax Autobaud No autobaud Default Configuration Exec-timeoutAutobaud 174Show line Syntax Exec-timeout minutes seconds No exec-timeoutSyntax Show line console telnet ssh 175Terminal history Following example displays the line configurationTerminal history size Console# show line console177 Maximum for the sum of all buffers isLine Commands Lldp enable global Lldp CommandsLldp enable interface SyntaxInterface configuration Ethernet Lldp timerSyntax Lldp timer seconds No lldp timer Default 30 secondsDefault Configuraiton Lldp reinit-delayLldp hold-multiplier Syntax Lldp hold-multiplier number No lldp hold-multiplierSyntax Lldp reinit-delay seconds No lldp reinit-delay Lldp tx-delaySyntax Lldp tx-delay seconds No lldp tx-delay Parameters Default value is 2 secondsLldp management-address Lldp optional-tlvUsage Guidelines No optional TLV is transmitted184 Clear lldp rxSyntax Show lldp configuration ethernet interface Show lldp configurationSwitch# show lldp configuration Show lldp local186 Show lldp neighborsSwitch# show lldp neighbors ethernet g1 Switch# show lldp neighbors187 Lldp Commands Name-The access list name using up to 32 characters Management access-listManagement ACL 189Permit management Console config# management access-class mlist190 Deny management Management Access-list Configuration mode191 192 Management access-classShow management access-class Show management access-listSyntax Show management access-list name Console# show management access-listConsole# show management access-class Syntax Show management access-class Default Configuration194 Test copper-port tdr PHY Diagnostics CommandsShow copper-ports tdr Console# test copper-port tdr g3Syntax Show copper-ports cable-length interface Show copper-ports cable-lengthPort must be active and working in 1000M 196Console# show copper-ports cable-length Show fiber-ports optical-transceiver197 Console# show fiber-ports optical-transceiver 198Console# show fiber-ports optical-transceiver detailed 199PHY Diagnostics Commands Console config# interface port-channel Port Channel CommandsInterface port-channel Interface range port-channelChannel-group Console config# interface range port-channelPort is not assigned to any port-channel 202Port channel load balance Console config-if#channel-group 1 mode onShow interfaces port-channel Syntax Show interfaces port-channel port-channel-number204 Default is both rx and tx Port Monitor CommandsInterface Configuration mode Port monitorShow ports monitor Syntax Show ports monitor Default Configuration206 207 Console# show ports monitorPort Monitor Commands Qos QoS CommandsShow qos Wrr-queue cos-map Following example displays a QoS mode210 Wrr-queue bandwidth Interface Configuration Ethernet, port channel modeFollowing example maps CoS 3 to queue 211Priority-queue out num-of-queues Following example assigns WRR weights to egress queuesAll queues are expedite queues 212Show qos interface Console config# priority-queue out num-of-queuesFollowing example sets queue 4, 3 to be expedite queues 213Console# show qos interface ethernet g1 queuing Qos map dscp-queue214 Syntax Qos trust cos dscp No qos trust Qos trust Global215 Syntax Qos cos default-cos No qos cos 216 Syntax Qos trust No qos trust Default ConfigurationQos trust Interface Qos cosSyntax Show qos map dscp-queue Show qos map217 Console# show qos map Dscp-queue map Following example displays the Dscp port-queue mapFollowing table describes the fields used above D1 x 10 + D2 = Value of DscpBy default, no Radius host is specified Radius CommandsRadius-server host Ip-address-IP address of the Radius server hostDefault is an empty string TimeoutRadius-server key Syntax Radius-server key key-string No radius-server keyRadius-server retransmit Console config# radius-server retransmitRadius-server source-ip 221Console config# radius-server timeout Radius-server timeout222 Syntax Show radius-servers Default Configuration Console config# radius-server deadtimeRadius-server deadtime Show radius-servers224 Following example displays the Radius server settingsConsole# show radius-servers Show rmon statistics Rmon CommandsConsole# show rmon statistics ethernet g1 225Field Description 226227 Rmon collection historyShow rmon collection history Console config-if#rmon collection history 1 intervalFollowing example displays all Rmon group statistics Console# show rmon collection history229 Show rmon history230 Console# show rmon history 5 errorsConsole# show rmon history 5 throughput 231 Console# show rmon history 5 other232 Rmon alarm233 Show rmon alarm-tableSyntax Show rmon alarm-table Default Configuration Show rmon alarmConsole# show rmon alarm-table Syntax Show rmon alarm numberConsole# show rmon alarm Following example displays Rmon 1 alarms235 236 Rmon eventSyntax Show rmon events Default Configuration Following example configures an event with the trap indexShow rmon events Following example displays the Rmon event tableConsole# show rmon events Show rmon logSyntax Show rmon log event Event-Event index. Range 0Console# show rmon log Following example displays the Rmon logging table239 Rmon table-size Console config# rmon table-size historyHistory table size is Log table size is 240There are no default communities defined Snmp CommandsSnmp-server community No snmp-server community community ip-addressDefault and DefaultSuper views exists Default SettingSnmp-server view 242Product specific Snmp-server filter243 Snmp-server location Snmp-server contactIncluded Syntax Snmp-server contact text No snmp-server contactConsole config# snmp-server enable traps Snmp-server enable trapsSyntax Snmp-server location text No snmp-server location 245Console config# snmp-server trap authentication Snmp-server trap authenticationSnmp-server host 246247 Snmp-server set248 Snmp-server groupSnmp-server user Console config# snmp-server group user-groupv3 priv readNo group entry exists Router context is translated to context in the MIB250 Console config# snmp-server user Following example configures a new Snmp Version 3 userSnmp-server v3-host 251Snmp-server engineID local Following example configures an SNMPv3 host252 Consoleconfig # snmp-server engineID local default Syntax Show snmp engineID Default SettingShow snmp engineid 253Show snmp Syntax Show snmp Default ConfigurationConsole# sh snmp 254Syntax Show snmp views viewname Show snmp views255 Syntax Show snmp groups groupname Show snmp groups256 Syntax Show snmp filters filtername Show snmp filters257 Syntax Show snmp users username Show snmp users258 259 Snmp Commands Spanning-tree mode Spanning-Tree CommandsSyntax Spanning-tree No spanning-tree Default Configuration Spanning-treeConsoleconfig# spanning-tree forward-time Consoleconfig# spanning-tree mode rstpSpanning-tree forward-time Seconds-Time in seconds. Range 4263 Spanning-tree hello-timeSpanning-tree max-age Consoleconfig# spanning-tree hello-time264 Consoleconfig# spanning-tree max-age Spanning-tree disableConsoleconfig# spanning-tree priority Spanning-tree prioritySpanning-tree cost Following example disables spanning-tree on g5Syntax Spanning-tree cost cost No spanning-tree cost Cost-The port path cost Range 1 200,000,000Spanning-tree port-priority Consoleconfig-if#spanning-tree port-prioritySpanning-tree portfast 267Consoleconfig-if#spanning-tree link-type shared Consoleconfig-if#spanning-tree portfastSpanning-tree link-type 268Console config # spanning-tree mst 1 priority Default number of hops isSpanning-tree mst priority Spanning-tree mst max-hopsConsoleconfig-if#spanning-tree mst 1 port-priority Console config # spanning-tree mst max-hopsSpanning-tree mst port-priority 270Spanning-tree mst cost Spanning-tree mst configurationInterface Long Short 271Instance mst Syntax Spanning-tree mst configuration Default SettingSyntax Instance instance-id add remove vlan vlan-range 272Revision mst Name mstSyntax Name string Syntax Revision value No revisionFollowing example sets the configuration revision to Default configuration revision number isShow mst Syntax Show current pendingSyntax Abort Default Setting Syntax Exit Default SettingExit mst Abort mstSpanning-tree bpdu Spanning-tree pathcost methodConsole# spanning-tree pathcost method long 276Clear spanning-tree detected-protocols Consoleconfig# spanning-tree bpdu floodingSyntax Spanning-tree bpdu filtering flooding 277Console# clear spanning-tree detected-protocols ethernet g1 Show spanning-treeFollowing example displays spanning-tree information 278Console# show spanning-tree 279280 281 282 283 284 285 286 Console# show spanning-tree mst-configuration287 288 289 290 Spanning-tree mst mstp-rstpRoot guard is disabled Consoleconfig# spanning-tree mst mstp-rstpInterface configuration Ethernet, port-channel Spanning-tree guard rootConsoleconfig-if#spanning-tree guard root Following example enable root guard on port g8292 Ip ssh port SSH CommandsIp ssh server Console config# crypto key generate dsa Syntax Crypto key generate dsa Default ConfigurationCrypto key generate dsa Crypto key generate rsaConsole config# crypto key generate rsa Syntax Crypto key generate rsa Default ConfigurationIp ssh pubkey-auth 295Crypto key pubkey-chain ssh Consoleconfig# crypto key pubkey-chain sshUser-key Syntax Key-string row key-string Key-string297 Show ip ssh Syntax Show ip ssh Default Configuration298 Show crypto key mypubkey Following example displays the SSH server configurationSyntax Show crypto key mypubkey rsa dsa Rsa-RSA key Dsa-DSA key300 Show crypto key pubkey-chain sshConsole# show crypto key mypubkey rsa Following example displays the SSH public called bob Console# show crypto key pubkey-chain sshConsole# show crypto key pubkey-chain ssh username bob 301SSH Commands Syntax Logging on no logging on Default Configuration Syslog CommandsLogging on LoggingLogging console Default is informationalAs described in the field descriptions Syntax Logging console level No logging consoleLogging buffered Default level is informationalLogging buffered size Syntax Logging buffered level No logging bufferedSyntax Clear logging Default Configuration Console config# logging buffered sizeClear logging Console# clear loggingLogging file Syntax Clear logging file Default ConfigurationClear logging file Syntax Logging file level No logging fileShow logging Syntax Show logging Default ConfigurationFollowing example clears messages from the logging file Console# clear logging fileShow logging file Syntax Show logging file Default ConfigurationConsole# show logging 309Show syslog-servers Syntax Show syslog-servers Default Configuration310 Console# show syslog-servers Following example displays the syslog server settings311 Syslog Commands System Management Timeout timeout-The default is 2000 millisecondsPing 313Following example displays a ping to IP address Traceroute314 315 316 Telnet Special Telnet Command characters317 318 Keywords Table319 Ports TableResume Following command switches to another open Telnet sessionSyntax Resume connection 320Hostname ReloadShow sessions Show usersConsole# show users Show system Exec modeConsole show sessions Syntax Show systemFollowing example displays the system information Show versionSyntax Show version 324 Console show systemSyntax Asset-tag tag No asset-tag Asset-tagTag-The device asset tag. Range 1- 16 characters 325Show system id Syntax Show system id Default ConfigurationConsole show system id 326Tacacs-server host Tacacs CommandsNo Tacacs host is specified 327Following example sets the authentication encryption key Tacacs-server timeoutTacacs-server key Following example specifies a TACACS+ hostTacacs-server source-ip Console config# tacacs-server timeout329 Syntax Show tacacs ip-address Show tacacsIp-address-Name or IP address of the host Console# show tacacsDisable EnableUser Interface Configure LoginSyntax Login Default Configuration Syntax ConfigureSyntax Exit Default Configuration ExitconfigurationAll command modes 333ExitEXEC Syntax End Default ConfigurationEnd Following example closes an active terminal sessionSyntax History No history Default Configuration Syntax Help Default ConfigurationHelp HistorySyntax Debug-mode Default Configuration Syntax History size number-of-commands No history sizeHistory size Debug-modeShow history Syntax Show history Default Configuration337 Show privilege Syntax Show privilege Default ConfigurationConsole# show history Console# show privilegeVlan database Vlan CommandsVlan Interface vlan Default-vlan disableConsole# vlan database Syntax Interface range vlan vlan-range all Interface range vlan341 Name Switchport access vlanSyntax Name string no name 342Console config-if#switchport access vlan Switchport trunk allowed vlan343 Switchport general allowed vlan Switchport trunk native vlanConsole config-if#switchport trunk allowed vlan add 2,5-8 Console config-if#switchport trunk native vlan345 Switchport general pvidIngress filtering is enabled Switchport general ingress-filtering disable346 Switchport forbidden vlan Switchport general acceptable-frame-type tagged-onlyAll frame types are accepted at ingress All VLANs allowedMap protocol protocols-group Console config-if#switchport forbidden vlan addFollowing example maps protocol ip-arp to the group named 348Ip internal-usage-vlan Switchport general map protocols-group vlanVlan-id-VLAN ID of the internal usage VLAN.Range Valid Vlan 349Show vlan Console config# ip internal-usage-vlanSyntax Show vlan tag vlan-id name vlan-name Following example displays all Vlan informationShow vlan internal usage Syntax Show vlan internal usage Default Configuration351 Show vlan protocols-groups Syntax Show vlan protocols-groups Default ConfigurationConsole# show vlan internal usage Following example displays protocols-groups informationConsole# show vlan protocols-groups Show interfaces switchport353 Console# show interface switchport ethernet g1 Switchport modeSyntax Switchport mode customer access trunk general 354 No switchport mode Switchport customer vlanNo Vlan is configured Vlan-id- Vlan ID of the customer356 Ip http server Web ServerIp http port Syntax Ip http port port-number No ip http portIp https server Default for the device is disabledIp https port Syntax Ip https port port-number No ip https portCrypto certificate generate Following example configures the https port number to359 Crypto certificate request Console enable# crypto certificate generate key-generateCertificate and the SSL RSA key pairs do not exist Following example regenerates a Https certificate361 Console# crypto certificate 1 requestSyntax Crypto certificate number import Crypto certificate importNumber-Specifies the certificate number. Range 1 362Ip https certificate Consoleconfig# crypto certificate 1 importCertificate number 363Crypto certificate export pkcs12 Console config# ip https certificateSyntax Crypto certificate number export pkcs12 364365 Following example exports the certificate and RSA keysConsole# crypto certificate 1 export pkcs12 Syntax Crypto certificate number import pkcs12 passphrase Crypto certificate import pkcs12Following example imports the certificate and RSA keys 366367 Syntax Show crypto certificate mycertificate number Show crypto certificate mycertificateFollowing example displays the certificate Console# show crypto certificate mycertificateShow ip https Show ip httpConsole# show ip http 370 Console# show ip httpsAaa authentication dot1x 802.1x CommandsConsole config# aaa authentication dot1x default none Method1 method2...-At least one from the following tableConsole config# dot1x system-auto-control Following example enables 802.1x globallyDot1x system-auto-control Dot1x port-controlConsole config-if#dot1x port-control auto Dot1x re-authenticationSyntax Dot1x re-authentication No dot1x re-authentication 373Dot1x re-authenticate Dot1x timeout re-authperiodConsole config-if#dot1x re-authentication Console config-if#dot1x timeout re-authperiodConsole# dot1x re-authenticate ethernet g8 Dot1x timeout quiet-period375 Console config-if#dot1x timeout quiet-period Dot1x timeout tx-period376 Dot1x max-req Dot1x timeout supp-timeoutSyntax Dot1x max-req count No dot1x max-req 377378 Dot1x timeout server-timeoutShow dot1x Console config# dot1x timeout server-timeoutSyntax Show dot1x ethernet interface 379Console# show dot1x ethernet g3 380Syntax Show dot1x users username username Show dot1x usersUsername-Supplicant username Range 1- 160 characters Following example displays 802.1X usersSyntax Show dot1x statistics ethernet interface Show dot1x statistics382 383 Switch# show dot1x statistics ethernet g1Dot1x auth-not-req User should be authorized to access the VlanSyntax Dot1x auth-not-req no dot1x auth-not-req 384Dot1x single-host-violation Dot1x multiple-hostsSyntax Dot1x multiple-hosts no dot1x multiple-hosts 385Forward trap Show dot1x advancedSyntax Show dot1x advanced ethernet interface 386Switch# show dot1x advanced ethernet g1 Switch# show dot1x advanced387 388 Console# show dot1x advanced ethernet g1
Related manuals
Manual 72 pages 22.37 Kb

5324 specifications

The Dell 5324 is a high-performance network switch that is designed to meet the demands of modern enterprise networking. This switch represents a blend of advanced features aimed at enhancing network efficiency, reliability, and scalability, which are crucial for businesses looking to optimize their infrastructure.

One of the standout features of the Dell 5324 is its Layer 3 routing capabilities. It supports static routing and various dynamic routing protocols, including RIP, OSPF, and BGP, allowing for efficient data transfer across complex networks. This capability is particularly beneficial for organizations that require robust inter-VLAN routing and seamless connectivity with multiple network segments.

The Dell 5324 comes equipped with 24 Gigabit Ethernet ports, which provide ample connectivity options for devices within the network. Additionally, it includes four 10 Gigabit SFP+ ports, enabling users to integrate high-speed uplinks easily. This flexibility allows businesses to expand their network as demand grows without the need for a completely new setup.

Power over Ethernet (PoE) support is another significant advantage of the Dell 5324, as it enables the switch to deliver both data and power to connected devices through a single Ethernet cable. This feature is particularly useful for powering IP phones, security cameras, and Wi-Fi access points, simplifying the overall cabling and ensuring a neater installation.

Furthermore, the Dell 5324 offers advanced security features that help protect the network from unauthorized access and potential threats. It includes features such as 802.1X port-based authentication, MAC address filtering, and VLAN segmentation, ensuring that only authorized devices can connect to the network.

The user-friendly web-based interface alongside command-line interface (CLI) access enhances manageability, allowing network administrators to monitor performance, configure settings, and troubleshoot issues with ease. In addition, the switch supports network automation protocols, which can streamline management tasks and improve efficiency.

The industrial-grade design of the Dell 5324 ensures its reliability in various environments, making it a suitable choice for data centers and enterprise networks alike. With its combination of performance, scalability, and security features, the Dell 5324 stands out as a capable solution for organizations looking to improve their network infrastructure. Its capabilities make it a versatile addition for businesses aiming for a robust and future-ready networking environment.