beautypg.com

Configuring 802.1x port authentication, In this chapter, 1x port authentication with netconf overview – Brocade Network OS NETCONF Operations Guide v4.1.1 User Manual

Page 505: 1x authentication configuration tasks, Chapter 30

background image

Network OS NETCONF Operations Guide

473

53-1003231-02

Chapter

30

Configuring 802.1x Port Authentication

In this chapter

802.1x port authentication with NETCONF overview . . . . . . . . . . . . . . . . . 473

802.1x authentication configuration tasks . . . . . . . . . . . . . . . . . . . . . . . . . 473

Interface-specific administrative tasks for 802.1x . . . . . . . . . . . . . . . . . . . 476

Checking 802.1x configurations. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 482

802.1x port authentication with NETCONF overview

This chapter provides procedures for configuring 802.1x authentication using NETCONF interfaces.
Refer to the Network OS Administrator’s Guide for the following related information:

Conceptual and overview information about the 802.1x port authentication and the 802.1x
protocol

Configuring 802.1x port authentication using the Network OS command line interface (CLI)

Through the NETCONF interface, you can perform the following operations related to 802.1x port
authentication:

Use the RPC to configure 802.1x port authentication globally and on a
per-interface basis.

Use the RPC to verify all or part of the global or per-port 802.1x port
authentication configuration.

802.1x port authentication parameters are defined in the brocade-dot1x YANG module. For
information about the brocade-dot1x YANG module, refer to the Network OS YANG Reference
Manual
.

802.1x authentication configuration tasks

The tasks in this section describe the common 802.1x operations that you may need to perform.
For complete configuration options using the NETCONF interface, refer to the Network OS YANG
Reference Manual
and the brocade-dot1x.yang source file.

Configuring authentication between the switch and CNA or NIC

To configure authentication, you must add a RADIUS server to perform the authentication, and then
enable 802.1x authentication globally. The authentication process attempts to connect to the first
RADIUS server. If the RADIUS server is not reachable, the next RADIUS server is contacted.
However, if the RADIUS server is contacted and the authentication fails, the authentication process
does not check for the next server in the sequence.