51
Figure 15
Configure AAA for 802.1X users by a RADIUS server
Internet
Switch
802.1X user
RADIUS server
Vlan-int2
10.1.1.1/24
Vlan-int3
10.1.1.2/24
Vlan-int4
GE1/0/1
Configuration procedure
NOTE:
Configure the interfaces and VLANs as shown in
. Make sure that the host can get a new IP address
manually or automatically and can access resources in the authorized VLAN after passing authentication.
1.
Configure the RADIUS server (iMC PLAT 5.0)
NOTE:
This example assumes that the RADIUS server runs iMC PLAT 5.0 (E0101), iMC UAM 5.0 (E0101), and
iMC CAMS 5.0 (E0101).
# Add an access device.
Log in to the iMC management platform, select the
Service
tab, and select
User Access Manager
>
Access
Device
from the navigation tree to enter the
Access Device List
page. Then, click
Add
to enter the
Add
Access Device
page and perform the following configurations:
Set the shared key for authentication and accounting to
expert
Specify the ports for authentication and accounting as 1812 and 1813 respectively
Select
LAN Access Service
as the service type
Select
HP(A-Series)
as the access device type
Select the access device from the device list or manually add the device whose IP address is 10.1.1.2
Adopt the default settings for other parameters and click
OK
to finish the operation.
NOTE:
The IP address of the access device specified above must be the same as the source IP address of the
RADIUS packets sent from the device, which is the IP address of the outbound interface by default, or
otherwise the IP address specified with the
nas-ip
or
radius nas-ip
command on the access device.