Enterasys Networks 9033900-04 manual 802.1x Port Authentication Commands

Models: 9033900-04

1 316
Download 316 pages 29.09 Kb
Page 214
Image 214

Command Groups

802.1x Port Authentication Commands

The access point supports IEEE 802.1x access control for wireless clients. This control feature prevents unauthorized access to the network by requiring a 802.1x client application to submit user credentials for authentication. Client authentication is then verified via by a RADIUS server

using EAP (Extensible Authentication Protocol) before the access point grants client access to the network. The commands are listed in Table A-13.

Table A-13 802.1x Access Control Commands

Command

Function

Mode

Page

 

 

 

 

802.1x

Configures 802.1x as disabled,

IC-W

A-89

 

supported, or required

IC-W: VAP

 

 

 

 

 

802.1x broadcast-key-refresh-rate

Sets the interval at which the

IC-W

A-91

 

primary broadcast keys are

IC-W: VAP

 

 

refreshed for stations using

 

 

 

802.1x dynamic keying

 

 

 

 

 

 

802.1x session-key-refresh-rate

Sets the interval at which unicast

IC-W

A-92

 

session keys are refreshed for

IC-W: VAP

 

 

associated stations using

 

 

 

dynamic keying

 

 

 

 

 

 

802.1x session-timeout

Sets the timeout after which a

IC-W

A-93

 

connected client must be re-

IC-W: VAP

 

 

authenticated

 

 

 

 

 

 

802.1x supplicant

Sets the username and

GC

A-94

 

password used by the access

 

 

 

point to authenticate with the

 

 

 

network.

 

 

 

 

 

 

mac-access permission

Sets filtering to allow or deny

IC-W

A-95

 

listed addresses

IC-W: VAP

 

 

 

 

 

mac-access entry

Enters a MAC address in the

IC-W

A-96

 

filter table

IC-W: VAP

 

 

 

 

 

mac-authentication server

Sets address filtering to be

IC-W

A-97

 

performed with local or remote

IC-W: VAP

 

 

options

 

 

 

 

 

 

mac-authentication session-

Sets the interval at which

IC-W

A-98

timeout

associated clients will be re-

IC-W: VAP

 

 

authenticated with the RADIUS

 

 

 

server authentication database

 

 

 

 

 

 

mac-authentication password

Sets the password the AP sends

IC-W

A-99

 

to the RADIUS server for

IC-W: VAP

 

 

authenticating clients

 

 

 

 

 

 

show authentication

Shows some 802.1x

Exec

A-100

 

authentication settings, as well

 

 

 

as the address filter table

 

 

 

 

 

 

show interface wireless

Shows some 802.11x

Exec

A-151

 

authentication settings

 

 

 

 

 

 

A-88

Page 214
Image 214
Enterasys Networks 9033900-04 802.1x Port Authentication Commands, Table A-13 802.1x Access Control Commands Function Mode