Operation Manual – 802.1xH3C S7500 Series Ethernet Switches Chapter 1 802.1x Configuration1-13z You can also specify to adopt RADIUS authentication scheme, with a localauthentication scheme as an alternative. In this case, the local authenticationscheme is adopted when the RADIUS server fails.Refer to AAA-RADIUS-HWTACACS-EAD Operation Manual for detailed informationabout AAA configuration.1.3 Basic 802.1x ConfigurationTo utilize 802.1x features, you need to perform basic 802.1x configuration.1.3.1 Prerequisitesz Configure ISP domain and its AAA scheme, specify the authentication scheme( RADIUS or a local scheme) .z For local authentication scheme, configure the service type of local users aslan-access.1.3.2 Configuring Basic 802.1x FunctionsTable 1-1 Configure basic 802.1x functionsTo do... Use the command... RemarksEnter system view system-view —Enable 802.1xglobally dot1x RequiredDisabled by defaultUse the following command in systemview:dot1x [ interface interface-list ]Enable 802.1x forthe specified ports Use the following command in portview:dot1xRequiredDisabled by defaultSpecify accesscontrol mode forthe specified portsdot1x port-control{ authorized-force |unauthorized-force | auto }[ interface interface-list ]Optionalauto mode by defaultSpecify accessmethod for thespecified portsdot1x port-method { macbased |portbased } [ interface interface-list ]Optionalmacbased methodby defaultSpecifyauthenticationmethod for 802.1xusersdot1x authentication-method{ chap | pap | eap }OptionalBy default, a switchperforms CHAPauthentication inEAP terminationmode.