Command Groups

802.1x Port Authentication Commands

The access point supports IEEE 802.1x access control for wireless clients. This control feature prevents unauthorized access to the network by requiring a 802.1x client application to submit user credentials for authentication. Client authentication is then verified via by a RADIUS server

using EAP (Extensible Authentication Protocol) before the access point grants client access to the network. The commands are listed in Table A-13.

Table A-13 802.1x Access Control Commands

Command

Function

Mode

Page

 

 

 

 

802.1x

Configures 802.1x as disabled,

IC-W

A-89

 

supported, or required

IC-W: VAP

 

 

 

 

 

802.1x broadcast-key-refresh-rate

Sets the interval at which the

IC-W

A-91

 

primary broadcast keys are

IC-W: VAP

 

 

refreshed for stations using

 

 

 

802.1x dynamic keying

 

 

 

 

 

 

802.1x session-key-refresh-rate

Sets the interval at which unicast

IC-W

A-92

 

session keys are refreshed for

IC-W: VAP

 

 

associated stations using

 

 

 

dynamic keying

 

 

 

 

 

 

802.1x session-timeout

Sets the timeout after which a

IC-W

A-93

 

connected client must be re-

IC-W: VAP

 

 

authenticated

 

 

 

 

 

 

802.1x supplicant

Sets the username and

GC

A-94

 

password used by the access

 

 

 

point to authenticate with the

 

 

 

network.

 

 

 

 

 

 

mac-access permission

Sets filtering to allow or deny

IC-W

A-95

 

listed addresses

IC-W: VAP

 

 

 

 

 

mac-access entry

Enters a MAC address in the

IC-W

A-96

 

filter table

IC-W: VAP

 

 

 

 

 

mac-authentication server

Sets address filtering to be

IC-W

A-97

 

performed with local or remote

IC-W: VAP

 

 

options

 

 

 

 

 

 

mac-authentication session-

Sets the interval at which

IC-W

A-98

timeout

associated clients will be re-

IC-W: VAP

 

 

authenticated with the RADIUS

 

 

 

server authentication database

 

 

 

 

 

 

mac-authentication password

Sets the password the AP sends

IC-W

A-99

 

to the RADIUS server for

IC-W: VAP

 

 

authenticating clients

 

 

 

 

 

 

show authentication

Shows some 802.1x

Exec

A-100

 

authentication settings, as well

 

 

 

as the address filter table

 

 

 

 

 

 

show interface wireless

Shows some 802.11x

Exec

A-151

 

authentication settings

 

 

 

 

 

 

A-88

Page 214
Image 214
Enterasys Networks 9033900-04 802.1x Port Authentication Commands, Table A-13 802.1x Access Control Commands Function Mode