3com 8807 User Guide

Page of 883
802.1x Configuration
225
The macbased keyword specifies to authenticate each user accessing through the 
port. And disconnection of a user does not affect other users. Whereas if you 
specify the portbased keyword, users can access a network without being 
authenticated if a user passes the authentication previously. But these users are 
denied when the one who passes the authentication first goes offline.
By default, 802.1x authentication method on the port is macbased. That is, 
authentication is performed based on MAC addresses.
Without NMM Application Mondule, the system cannot perform traffic statistics 
for macbased users. Because the system performs traffic statistics only for ports 
instead of multiple users connecting with the same port, the system can perform 
traffic statistics only for portbased users.
Checking the Users that 
Log on the Switch via 
Proxy
The following commands are used for checking the users that log on the switch 
via proxy.
Perform the following configuration in system view or Ethernet port view.
These commands take effect on the ports specified by the interface-list parameter 
when executed in system view. The parameter interface-list cannot be input when 
the command is executed in Ethernet Port view and it has effect only on the 
current interface. After globally enabling proxy user detection and control in 
system view, only if you enable this feature on a specific port can this 
configuration take effects on the port.
Setting Supplicant 
Number on a Port
The following commands are used for setting number of users allowed by 802.1x 
on specified port. When no port is specified, all the ports accept the same number 
of supplicants.
Perform the following configuration in system view or Ethernet port view.
Table 186   Set port access control method
Operation 
Command 
Set port access control method 
dot1x port-method { macbased | 
portbased } [ interface interface-list ] 
Restore the default port access control 
method 
undo dot1x port-method [ interface 
interface-list ]
Table 187   Check the users that log on the switch via proxy
Operation 
Command 
Enable the check for access users via proxy 
dot1x supp-proxy-check { logoff | trap } [ 
interface interface-list ] 
Cancel the check for access users via proxy 
undo dot1x supp-proxy-check { logoff | 
trap } [ interface interface-list ]
Table 188   Setting maximum number of users via specified port
Operation 
Command 
Set maximum number of users via specified 
port 
dot1x max-user user-number [ interface 
interface-list ]