As for the dot1x version-usercommand, if you execute it in system view without specifying the interface-listargument, the command applies to all ports. You can also execute this command in port view. In this case, this command applies to the current port only and the interface-listargument is not needed.

Enabling DHCP-triggered Authentication

After performing the following configuration, 802.1x allows running DHCP on access users, and users are authenticated when they apply for dynamic IP addresses through DHCP.

Follow these steps to enable DHCP-triggered authentication:

 

To do…

 

Use the command…

 

Remarks

 

Enter system view

 

system-view

 

 

 

 

 

 

 

 

Enable DHCP-triggered

 

 

 

Required

 

 

dot1x dhcp-launch

 

By default, DHCP-triggered

 

authentication

 

 

 

 

 

 

authentication is disabled.

 

 

 

 

 

 

 

 

 

 

 

Configuring Guest VLAN

Follow these steps to configure Guest VLAN:

 

To do…

Use the command…

Remarks

 

 

Enter system view

system-view

 

 

 

 

 

 

 

 

 

Required

 

 

Configure the access control

dot1x port-method portbased

The default access control

 

 

method on ports is MAC-based.

 

 

method on ports

 

 

 

That is, the macbased

 

 

 

 

 

 

 

 

keyword is used by default.

 

 

 

 

 

 

 

Enable the Guest VLAN

dot1x guest-vlan vlan-id

Required

 

 

By default, the Guest VLAN

 

 

function

[ interface interface-list ]

 

 

function is disabled.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

zThe Guest VLAN function is available only when the device operates in the port-based access control mode.

zOnly one Guest VLAN can be configured for each device.

zThe Guest VLAN function cannot be implemented if you configure the dot1x dhcp-launchcommand on the device to enable DHCP-triggered authentication. This is because the device does not send authentication packets unsolicitedly in that case.

1-17

Page 238
Image 238
3Com WX3000 Enabling DHCP-triggered Authentication, Configuring Guest Vlan, Dot1x dhcp-launch, Dot1x port-method portbased