Operation Manual – 802.1xH3C S3600 Series Ethernet Switches-Release 1510 Chapter 1 802.1x Configuration1-13z If you specify to adopt the RADIUS scheme, the supplicant systems areauthenticated by a remote RADIUS server. In this case, you need to configureuser names and passwords on the RADIUS server and perform RADIUSclient-related configuration on the switches.z If you specify to adopt a local authentication scheme, you need to configure usernames and passwords manually on the switches. Users can pass theauthentication through 802.1x client if they provide the user names and passwordsthat match those configured on the switches.z You can also specify to adopt RADIUS authentication scheme, with a localauthentication scheme as a backup. In this case, the local authentication schemeis adopted when the RADIUS server fails.Refer to the AAA&RADIUS&RADIUS&HWTACACS&EAD Operation Manual fordetailed information about AAA scheme configuration.1.3 Basic 802.1x ConfigurationTo utilize 802.1x features, you need to perform basic 802.1x configuration.1.3.1 Prerequisitesz Configure ISP domain and the AAA scheme to be adopted. You can specify aRADIUS scheme or a local scheme.z Ensure that the service type is configured as lan-access (by using theservice-type command) if local authentication scheme is adopted.1.3.2 Configuring Basic 802.1x FunctionsTable 1-1 Configure basic 802.1x functionsOperation Command DescriptionEnter system view system-view —Enable 802.1xglobally dot1xRequiredBy default, 802.1x is disabledglobally.Use the following commandin system view:dot1x [ interfaceinterface-list ]Enable 802.1x forspecified portsUse the following commandin port view:dot1xRequiredBy default, 802.1x is disabledon all ports.