132
To do…
Use the command…
Remarks
Configure MAC
authentication
See the chapter ―MAC authentication
configuration‖
Configure at least one type of
authentication.
Configure Layer-2 portal
authentication
See the chapter ―Portal configuration‖
NOTE:
802.1X authentication must use MAC-based access control.
Triple authentication configuration examples
Triple authentication basic function configuration example
Network requirements
As shown in
, the terminals are connected to a switch to access the IP network. It is required to
configure triple authentication on the Layer-2 interface of the switch that connects to the terminals, so that
a terminal passing one of the three authentication methods, 802.1X authentication, portal authentication,
and MAC authentication, can access the IP network. More specifically,
Configure static IP addresses in network 192.168.1.0/24 for the terminals.
Use the remote RADIUS server to perform authentication, authorization, and accounting and
configure the switch to send usernames carrying no ISP domain names to the RADIUS server.
The local portal authentication server on the switch uses listening IP address 4.4.4.4. The switch
sends a default authentication page to the web user and forwards authentication data using HTTP.
Figure 45
Network diagram for triple authentication basic configuration
IP network
RADIUS server
Switch
1.1.1.2/24
802.1X client
Printer
Web user
Vlan-int3
3.3.3.1
Vlan-int8
192.168.1.1/24
GE1/0/1
Vlan-int1
1.1.1.1
Configuration procedure