1-19To do… Use the command… RemarksEnter Ethernet interface view interface interface-typeinterface-number —Configure the Auth-Fail VLANfor the portdot1x auth-fail vlanauthfail-vlan-idRequiredBy default, a port is configuredwith no Auth-Fail VLAN.Different ports can be configured with different Auth-Fail VLANs, but a port can be configured with onlyone Auth-Fail VLAN.Displaying and Maintaining 802.1XTo do… Use the command… RemarksDisplay 802.1X sessioninformation, statistics, orconfiguration information ofspecified or all portsdisplay dot1x [ sessions |statistics ] [ interfaceinterface-list ]Available in any viewClear 802.1X statistics reset dot1x statistics[ interface interface-list ] Available in user view802.1X Configuration ExampleNetwork requirementsz It is required to use the access control method of macbased on the port GigabitEthernet1/0/1 tocontrol clients.z All clients belong to default domain aabbcc.net, which can accommodate up to 30 users. RADIUSauthentication is performed at first, and then local authentication when no response from theRADIUS server is received. If the RADIUS accounting fails, the device logs users off.z A server group with two RADIUS servers is connected to the switch. The IP addresses of theservers are 10.1.1.1 and 10.1.1.2 respectively. Use the former as the primary authentication/accounting server, and the latter as the secondary authentication/ accounting server.z Set the shared key for the device to exchange packets with the authentication server as name, andthat for the device to exchange packets with the accounting server as money.z Specify the device to try up to five times at an interval of 5 seconds in transmitting a packet to theRADIUS server until it receives a response from the server, and to send real time accountingpackets to the accounting server every 15 minutes.z Specify the device to remove the domain name from the username before passing the username tothe RADIUS server.