70NOTE:If EAP relay mode is used, the user-name-format command configured in RADIUS scheme view does nottake effect. The access device sends the authentication data from the client to the server without anymodification.Setting the port authorization stateThe port authorization state determines whether the client is granted access to the network. You cancontrol the authorization state of a port by using the dot1x port-control command and the followingkeywords:• authorized-force—Places the port in the authorized state, enabling users on the port to access thenetwork without authentication.• unauthorized-force—Places the port in the unauthorized state, denying any access requests fromusers on the port.• auto—Places the port initially in the unauthorized state to allow only EAPOL packets to pass. Aftera user passes authentication, sets the port in the authorized state to allow access to the network. Youcan use this option in most scenarios.To set the authorization state of a port:Step Command Remarks1. Enter system view. system-view N/A2. Enter Ethernet interfaceview.interface interface-typeinterface-number N/A3. Set the port authorizationstate.dot1x port-control { authorized-force |auto | unauthorized-force } By default, auto applies.Specifying an access control methodStep Command Remarks1. Enter system view. system-view N/A2. Enter Ethernet interface view. interface interface-typeinterface-number N/A3. Specify an access controlmethod.dot1x port-method { macbased |portbased }By default, MAC-based accesscontrol applies.Setting the maximum number of concurrent 802.1Xusers on a portPerform this task to prevent the system resources from being overused.To set the maximum number of concurrent 802.1X users on a port: