This section describes how to configure 802.1x user authentication.
For users who use 802.1x to access the network, the FW supports only RADIUS server authentication and local authentication.
This section describes the authentication domain configuration for 802.1x users. For other 802.1x access configurations, see Configuring 802.1x Using the Web UI.
802.1x authentication applies only to user access. After users access the network, the FW cannot implement user-specific policy control. To address this issue, you can configure portal authentication to authenticate users again.
Configure user information on the FW based on the locations and organizational structure of users.
Users on the local device
Create users in the following ways:
In User Management List, click Add to create users.
Parameter |
Description |
|---|---|
User Name |
Login name used for authentication Each login name (account) must be unique in its authentication domain. |
Display Name |
Display name of a user A display name is a user identifier and cannot be used to initiate an authentication request. You are advised to use the employees' names as their display names for easy recognition and management. Users can share a display name. This parameter is unavailable when you create users in batches. |
Description |
Description of a user Describe users in a way that makes it easy to find and maintain users. |
Password |
User password |
Confirm Password |
User password entered again for confirmation |
Users on the server
The RADIUS accounting scheme and the RADIUS authorization scheme apply only to user-defined portal authentication, SSL VPN access, L2TP/L2TP over IPSec, IPSec access, administrator access, and 802.1x access scenarios in which the firewall participates in user authentication.