3Com Switch 8800 Configuration Guide Chapter 39 802.1x Configuration
39-8
Perform the following configuration in system view.
Table 39-6 Set the Authentication in DHCP Environment
Operation Command
Disable the switch to trigger the user ID
authentication over the users who configure
static IP addresses in DHCP environment
dot1x dhcp-launch
Enable the switch to trigger the authentication
over them undo dot1x dhcp-launch
By default, the switch can trigger the user ID authentication over the users who
configure static IP addresses in DHCP environment.
39.2.7 Configuring Authentication Method for 802.1x User
The following commands can be used to configure the authentication method for
802.1x user. Three kinds of methods are available: PAP authentication (RADIUS se rver
must support PAP authentication), CHAP authentication (RADIUS server must support
CHAP authentication), EAP relay authentication (switch send authentication
information to RADIUS server in the form of EAP packets directly and RADIUS server
must support EAP authentication).
Perform the following configuration in system view.
Table 39-7 Configure authentication method for 802.1x user
Operation Command
Configure authentication method for
802.1x user
dot1x authentication-method { chap |
pap | eap md5-challenge}
Restore the default authentication
method for 802.1x user undo dot1x authentication-method
By default, CHAP authentication is used for 802.1x user authentication.
39.2.8 Enabling/Disabling Guest VLAN
If Guest VLAN is enabled, a switch broadcasts active authentication packets to all
802.1x-enabled ports. The ports not sending response packets are added to Guest
VLAN when the maximum number of re-authentications is reached. Users in a Guest
VLAN can utilize resources in the Guest VLAN without undergoing the 802.1x
authentication, but they can utilize the resources outside the Guest VLAN only when
they have passed the 802.1x authentication. In this way, unauthenticated users can still
perform operations such as accessing some resources with the 802.1x client not
installed, and upgrading 802.1x client.