Verifying the configuration – H3C Technologies H3C WX3000E Series Wireless Switches User Manual

Page 255

Advertising
background image

241

# Set the 802.1X authentication method to EAP.

[AC] dot1x authentication-method eap

# Set the port security mode of WLAN-ESS 1 to userLoginSecureExt. In this mode, the port performs
802.1X authentication, implements MAC-based access control, and allows more than one

802.1X user.

[AC] interface WLAN-ESS 1

[AC-WLAN-ESS1] port-security port-mode userlogin-secure-ext

# Enable the MAC-based VLAN function and configure VLAN 2 as the guest VLAN.

[AC-WLAN-ESS1] port link-type hybrid

[AC-WLAN-ESS1] port hybrid vlan 1 to 2 untagged

[AC-WLAN-ESS1] port hybrid pvid vlan 2

[AC-WLAN-ESS1] mac-vlan enable

[AC-WLAN-ESS1] dot1x guest-vlan 1

[AC-WLAN-ESS1] undo dot1x handshake

[AC-WLAN-ESS1] undo dot1x multicast-trigger

[AC-WLAN-ESS1] quit

# Configure the WLAN service template.

[AC] wlan service-template 1 clear

[AC-wlan-st-1] ssid SSID1

[AC-wlan-st-1] bind WLAN-ESS 1

[AC-wlan-st-1] authentication-method open-system

[AC-wlan-st-1] service-template enable

[AC-wlan-st-1] quit

# Configure the service template of AP.

[AC] wlan ap 1 model WA2100

[AC-wlan-ap-1] serial-id 210235A29G007C000020

[AC-wlan-ap-1] radio 1

[AC-wlan-ap-1-radio-1] service-template 1

[AC-wlan-ap-1-radio-1] radio enable

[AC-wlan-ap-1-radio-1] quit

Verifying the configuration

# Before Client 1 is authenticated (using the username of mac and MAC address of 000f-e2cc-6a21), the

guest VLAN function takes effect. You can use the display mac-vlan all command to display the
MAC-to-VLAN mapping.

[AC] display mac-vlan all

The following MAC VLAN addresses exist:

S:Static D:Dynamic

MAC ADDR MASK VLAN ID PRIO STATE

--------------------------------------------------------

000f-e2cc-6a21 ffff-ffff-ffff 1 0 D

Total MAC VLAN address count:1

# If Client 1 initiates authentication and passes the authentication, you can use the display connection
command to display the user information, and use the display mac-vlan all command to verify that the

MAC-to-VLAN mapping entry has been removed.

[AC] display connection username mac@sun

Index=18 , Username=mac@sun

Advertising