beautypg.com

Interface-specific administrative tasks for 802.1x, 1x readiness check, Configuring 802.1x on specific interface ports – Brocade Network OS NETCONF Operations Guide v4.1.1 User Manual

Page 508

background image

476

Network OS NETCONF Operations Guide

53-1003231-02

Interface-specific administrative tasks for 802.1x

30

Interface-specific administrative tasks for 802.1x

It is essential to configure the 802.1x port authentication protocol globally on the Brocade VDX
hardware, and then enable 802.1x and make customized changes for each interface port. Because
802.1x was enabled and configured in

“802.1x authentication configuration tasks”

, use the

administrative tasks in this section to make any necessary customizations to specific interface port
settings.

802.1x readiness check

Before configuring 802.1x for specific interface ports, Brocade recommends that you perform a
readiness check to ensure the port is 802.1x-capable. You cannot perform this check from the
NETCONF interface. The check can be performed only from the command line interface of the
device by issuing the dot1x test eapol-capable command. Refer to the Network OS Administrator’s
Guide
for details.

Configuring 802.1x on specific interface ports

To configure 802.1x port authentication on a specific interface port, perform the following steps.
Repeat this task for each interface port you wish to modify.

1. Issue the RPC to configure the node in the

urn:brocade.com:mgmt:brocade-interface namespace.

2. Under the node, specify the , ,

, or node element.

NOTE

You cannot configure 802.1x authentication on a port-channel.

3. Under the , , , or

node, include the leaf element and specify the name of
the interface on which you want to configure 802.1x authentication. Specify the interface in
[rbridge-id/]slot/port format.

4. Under the , , , or

node, include the node element from the
urn:brocade.com:mgmt:brocade-dot1x namespace.

5. Under the node, include the empty leaf element to configure 802.1x

authentication for the port interface.

6. Issue the RPC to save the running-config file to the startup-config file.

The following example configures 802.1x authentication on 10-gigabit Ethernet port 22/0/1.