Secondary IP: Enter the IP address of the alternate accounting server.
Accounting Port: Set the UDP port of accounting server(s). The default port is 1813.
Accounting Key: Set the shared password for the switch and the accounting
servers to exchange messages.
Note:
1. The 802.1X function takes effect only when it is enabled globally on the switch and for the port.
2. The 802.1X function can not be enabled for LAG member ports. That is, the port with 802.1X
function enabled can not be added to the LAG.
3. The 802.1X function should not be enabled for the port connected to the authentication server.
In addition, the authentication parameters of the switch and the authentication server should
be the same.
Configuration Procedure:
Step Operation Description
1 Connect an authentication
server to the switch and do
some configuration.
Required. Record the information of the client in the LAN to
the authentication server and configure the corresponding
authentication username and password for the client.
2 Install the 802.1X client
software.
Required. For the client computers, you are required to
install the 802.1X software TpSupplicant provided on the
CD. For the installation guide, please refer to Appendix C:
802.1X Client Software.
3 Configure the 802.1X
globally.
Required. By default, the global 802.1X function is disabled.
On the Network Security802.1XGlobal Config page,
configure the 802.1X function globally.
4 Configure the parameters of
the authentication server
Required. On the Network Security802.1XRadius
Server page, configure the parameters of the server.
5 Configure the 802.1X for the
port.
Required. On the Network Security802.1XPort
Config page, configure the 802.1X feature for the port of
the switch basing on the actual network.
12.6 PPPoE Config
PPPoE Circuit-ID Tag Overview
In the ATM-based network, the BRAS (Broadband Remote Access Server) vendors need to
acquire the unique information from DSL (digital subscriber line) for RADIUS (Remote
Authentication Dial In User Service) authentication and accounting processes. The PPPoE
Circuit-ID Insertion feature uses a PPPoE intermediate agent function on the DSLAM. The DSLAM
(Digital Subscriber Line Multiplexer) attaches a tag to the PPPoE discovery packets. This tag is
called the PPPoE Vendor-Specific tag and it contains a unique line identifier. The BRAS receives
the tagged packet, decodes the tag, and uses the Circuit-ID field of that tag as a NAS-Port-ID
attribute in the RADIUS authentication packet for PPP authentication and AAA (authentication,
authorization, and accounting) access requests.
In this Chapter the switch will work as a DSLAM.
217