11 802.1x authentication configuration tasks

802.1x authentication configuration tasks

The tasks in this section describe the common 802.1x operations that you will need to perform. For a complete description of all the available 802.1x CLI commands for the Dell FCoE hardware, see the Converged Enhanced Ethernet Command Reference.

Configure authentication

between the switch and CNA or NIC

For complete information on the aaaConfig command, see the Fabric OS Command Reference and the Fabric OS Administrator’s Guide.

NOTE

The aaaConfig command attempts to connect to the first RADIUS server. If the RADIUS server is not reachable, the next RADIUS server is contacted. However, if the RADIUS server is contacted and the authentication fails, the authentication process does not check for the next server in the sequence.

To configure authentication, perform the following steps.

1.Connect to the switch and log in using an account assigned to the admin role.

2.Add the RADIUS to the switch as the authentication server. This Fabric OS CLI command moves the new RADIUS server to the top of the access list.

switch:admin> aaaconfig --add 10.2.2.147 -conf radius 1

3. Enter global configuration mode.

switch:admin>cmsh switch#configure t

4. Enable 802.1x authentication globally

switch(config)#dot1x enable

5. Enter the copy command to save the running-configfile to the startup-configfile.

switch(config)#end

switch#copy running-config startup-config

Interface-specific administrative tasks for 802.1x

It is essential to configure the 802.1x port authentication protocol globally on the Dell FCoE hardware, and then enable 802.1x and make customized changes for each interface port. Since 802.1x was enabled and configured in “802.1x authentication configuration tasks”, use the administrative tasks in this section to make any necessary customizations to specific interface port settings.

NOTE

802.1x port authentication functions only on external ports.

112

Dell Converged Enhanced Ethernet Administrator’s Guide

 

53-1002116-01

Page 130
Image 130
Dell 53-1002116-01 manual 802.1x authentication configuration tasks, Interface-specific administrative tasks for