The following example shows how to authenticate the dot1x users by a RADIUS server. The management IP address is 10.100.5.33/24.
- Enable routing for the switch.
- Select Routing > Basic > IP Configuration.
A screen similar to the following displays.

- For Routing Mode, select the Enable radio button.
- Click Apply to save the settings.
- Select Routing > Basic > IP Configuration.
- Assign IP address 192.168.1.1/24 to the interface 1/0/1.
- Select Routing > Advanced > IP Interface Configuration.
A screen similar to the following displays.

- Under IP Interface Configuration, scroll down and select the Interface 1/0/1 check box.
Now 1/0/1 appears in the Interface field at the top.
- Enter the following information:
- In the IP Address field, enter 192.168.1.1.
- In the Subnet Mask field, enter 255.255.255.0.
- In the Routing Mode field, select Enable.
- Click Apply to save the settings.
- Select Routing > Advanced > IP Interface Configuration.
- Assign IP address 10.100.5.33/24 to interface 1/0/19:
- Select Routing > Advanced > IP Interface Configuration.
A screen similar to the following displays.

- Scroll down and select the interface 1/0/19 check box.
Now 1/0/19 appears in the Interface field at the top.
- Enter the following information:
- In the IP Address field, enter 10.100.5.33.
- In the Subnet Mask field, enter 255.255.255.0.
- In the Routing Mode field, select Enable.
- Click Apply to save the settings.
- Select Routing > Advanced > IP Interface Configuration.
- Create an authentication name list.
- Select Security > Management Security > Login > Authentication List.
A screen similar to the following displays.

- Select the check box before dot1xList.
- In the 1 list, select Radius.
- Click Apply.
- Select Security > Management Security > Login > Authentication List.
- Set port 1/0/19 to force authorized mode. (In this case, the RADIUS server is connected to this interface.)
- Select Security > Port Authentication > Advanced > Port Authentication.
A screen similar to the following displays.

- Scroll down and select the Interface 1/0/19 check box.
Now 1/0/19 appears in the Interface field at the top.
- In the Control Mode list, select Force Authorized.
- Click Apply to save the settings.
- Select Security > Port Authentication > Advanced > Port Authentication.
- Enable dot1x on the switch.
- Select Security > Port Authentication > Server Configuration.
A screen similar to the following displays.

- For Administrative Mode, select the Enable radio button.
- In the Login list, select dot1xList.
- Click Apply to save settings.
- Select Security > Port Authentication > Server Configuration.
- Configure the RADIUS authentication server.
- Select Security > Management Security > Server Configuration.
A screen similar to the following displays.

- In the Server Address field, enter 10.100.5.17.
- In the Secret Configured field, select Yes.
- In the Secret field, enter 123456.
- In the Primary Server field, select Yes.
- In the Message Authenticator field, select Enable.
- Click Add.
- Select Security > Management Security > Server Configuration.
- Enable accounting.
- Select Security > Management Security > RADIUS > Radius Configuration.
A screen similar to the following displays.

- In the Server Address field, enter 10.100.5.17.
- In the Accounting Mode field, select Enable.
- Click Apply.
- Select Security > Management Security > RADIUS > Radius Configuration.
- Configure the accounting server.
- Select Security > Management Security > RADIUS > Radius Accounting Server Configuration.
A screen similar to the following displays.

- In the Accounting Server Address field, enter 10.100.5.17.
- In the Accounting Mode field, select Enable.
- Click Apply.
- Select Security > Management Security > RADIUS > Radius Accounting Server Configuration.
For more information, see the following support articles:
- What is 802.1x port security and how does it work with my managed switch?
- How do I authentic dot1x users by a radius server using CLI commands on my managed switch?
This article applies to the following managed switches and their respective firmware:
- M5300 - firmware version 10.0.0.x
-
- M5300-28G (GSM7228S)
- M5300-5G (GSM7252S)
- M5300-28G3 (GSM7328Sv2h2)
- M5300-52G3 (GSM7352Sv2h2)
- M5300-28G_POE+ (GSM7228PSv1h2)
- M5300-52G-POE+ (GSM7252PSv1h2)
- M5300-28GF3 (GSM7328FSv2)
- M4100 - firmware version 10.0.1.x
-
- M4100-26G (GSM7224v2h2)
- M4100-50G (GSM7248v2h2)
- M4100-26G-POE (GSM7226Pv1h1)
- M4100-50G-POE+ (GSM7248Pv1h1)
- M4100-26G-POE (FSM7226Pv1h1)
- M4100-50-POE (FSM7250Pv1h1)
- M4100-D12G (GSM5212v1h1)
- M4100-D10-POE (FSM5210Pv1h1)
- M7100 - firmware version 10.0.1.x
-
- M7100-24X (XSM7224)
- XSM7224S - firmware version 9.0.1.x