17 dot1x privateclient enable, X privateclient enable – PLANET WGSW-50040 User Manual

Page 351

Advertising
background image

Commands for Security Function Chapter 6 Commands for TACACS+

authentication. When either of the above two kinds of access control is applied, un-authenticated

host cannot access any resources in the network.

When user based access control is applied, un-authenticated users can only access limited

resources of the network. The user based access control falls into two kinds – the standard access

control and the advanced access control. The standard user based access control does not limit the

access to the limited resources when the host is not authenticated yet. While the user based

advanced access control can control the access to the limited resources before authentication is

done.

Webbased access management is used mostly in layer switch. The global configuration of WEB

authentication agent and HTTP redirection address is needed before setting the port to Webbased

access management. Webbased access management is conflicted with the command of ip dhcp

snooping binding user-control.

Notes: The 802.1x free resource must be configured first for standard control method based on

user.

Example:

To configure the standard control method based on port for Etherent1/4.

Switch(Config-If-Ethernet1/4)#dot1x port-method portbased

22.17 dot1x privateclient enable

Command:

dot1x privateclient enable

no dot1x privateclient enable

Function:

To configure the switch to force the authentication client to use private 802.1x authentication

protocol. The no prefix will disable the command and allow the authentication client to use the

standard 802.1x authentication protocol.

Command:

Global Mode.

Default:

Private 802.1x authentication packet format is disabled by default.

Usage Guide:

To implement integrated solution, the switch must be enabled to use private 802.1x protocol, or

many applications will not be able to function. If the switch forces the authentication client to use

private 802.1x protocol, the standard client will not be able to work.

Example:

Advertising