102
[Router] interface vlan-interface 2
[Router-Vlan-interface2] dhcp select relay
# Correlate VLAN interface 2 to the DHCP server group.
[Router-Vlan-interface2] dhcp relay server-select 1
[Router-Vlan-interface2] quit
3.
Configure a RADIUS scheme and an ISP domain.
For more information about the configuration procedure, see "
4.
Configure 802.1X.
# Configure the free IP.
[Router] dot1x free-ip 192.168.2.0 24
# Configure the redirect URL for client software download.
[Router] dot1x url http://192.168.2.3
# Enable 802.1X globally.
[Router] dot1x
# Enable 802.1X on the port.
[Router] interface gigabitethernet 1/0/1
[Router-GigabitEthernet1/0/1] dot1x
Verification
Use
display dot1x
to display the 802.1X configuration. After the host obtains an IP address from a
DHCP server, use
ping
from the host to ping an IP address on the network segment specified by free IP.
C:\>ping 192.168.2.3
Pinging 192.168.2.3 with 32 bytes of data:
Reply from 192.168.2.3: bytes=32 time<1ms TTL=128
Reply from 192.168.2.3: bytes=32 time<1ms TTL=128
Reply from 192.168.2.3: bytes=32 time<1ms TTL=128
Reply from 192.168.2.3: bytes=32 time<1ms TTL=128
Ping statistics for 192.168.2.3:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
The output shows that you can access that segment before passing 802.1X authentication.
Before passing 802.1X authentication, if a user uses a web browser to access any external website, the
user is redirected to the web server, which provides the 802.1X client software download service. Enter
the external website address in the address bar in the format of X.X.X.X in dotted decimal notation (for
example, 3.3.3.3 or http://3.3.3.3). The external website address should not be on the freely
accessible network segment.