1-19
[Device-radius-2000] key authentication abc
[Device-radius-2000] key accounting abc
[Device-radius-2000] user-name-format without-domain
[Device-radius-2000] quit
# Configure authentication domain
system
and specify to use RADIUS scheme 2000 for users of the
domain.
[Device] domain system
[Device-isp-system] authentication default radius-scheme 2000
[Device-isp-system] authorization default radius-scheme 2000
[Device-isp-system] accounting default radius-scheme 2000
[Device-isp-system] quit
# Enable 802.1X globally.
[Device] dot1x
# Enable 802.1X for port GigabitEthernet 1/0/2.
[Device] interface GigabitEthernet 1/0/2
[Device-GigabitEthernet1/0/2] dot1x
# Set the port access control method to
portbased
.
[Device-GigabitEthernet1/0/2] dot1x port-method portbased
# Set the port access control mode to
auto
.
[Device-GigabitEthernet1/0/2] dot1x port-control auto
[Device-GigabitEthernet1/0/2] quit
# Create VLAN 10.
[Device] vlan 10
[Device-vlan10] quit
# Specify port GigabitEthernet 1/0/2 to use VLAN 10 as its guest VLAN.
[Device] dot1x guest-vlan 10 interface GigabitEthernet 1/0/2
You can use the
display current-configuration
or
display interface GigabitEthernet 1/0/2
command
to view your configuration. You can also use the
display vlan 10
command in the following cases to
verify whether the configured guest VLAN functions:
z
When no users log in.
z
When a user goes offline.
After a user passes the authentication successfully, you can use the
display interface
GigabitEthernet 1/0/2
command to verity that port GigabitEthernet 1/0/2 has been added to the
assigned VLAN 5.
ACL Assignment Configuration Example
Network requirements
As shown in
Figure 1-13
, a host is connected to port GigabitEthernet 1/0/1 of the device and must pass
802.1X authentication to access the Internet.
z
Configure the RADIUS server to assign ACL 3000.
z
Enable 802.1X authentication on port GigabitEthernet 1/0/1 of the device, and configure ACL 3000.
After the host passes 802.1X authentication, the RADIUS server assigns ACL 3000 to port
GigabitEthernet 1/0/1. As a result, the host can access the Internet but cannot access the FTP server,
whose IP address is 10.0.0.1.