Configuring 802.1x, Configuration prerequisites, Recommended configuration procedure – H3C Technologies H3C WX3000E Series Wireless Switches User Manual

Page 394: Configuring 802.1x globally

Advertising
background image

378

With MAC-based access control, each user is separately authenticated on a port. When a user logs

off, no other online users are affected.

Configuring 802.1X

Configuration prerequisites

Configure an ISP domain and AAA scheme (local or RADIUS authentication) for 802.1X users. For
more information, see "

Configuring AAA

" and "

Configuring RADIUS

."

If RADIUS authentication is used, create user accounts on the RADIUS server.

If local authentication is used, create local user accounts on the access device and set the service
type to LAN-access.

If you want to use EAP relay when the RADIUS server does not support any EAP authentication
method or no RADIUS server is available, configure the EAP server function on your network access

device.

NOTE:

Configure 802.1X on a wired port. Wireless ports support only the port security feature, and the port
security is enabled by default on the wireless ports.

Recommended configuration procedure

Task Description

1. Configuring 802.1X globally

Required.
Enable 802.1X authentication globally and configure the authentication
method and advanced parameters.
By default, 802.1X authentication is disabled globally.

2. Configuring 802.1X on a port

Required.
Enable 802.1X authentication on specified ports and configure 802.1X
parameters for the ports.
By default, 802.1X authentication is disabled on a port.

Configuring 802.1X globally

1.

From the navigation tree, select Authentication > 802.1X.

Advertising