49
[SwitchB] radius scheme scheme2
[SwitchB-radius-scheme2] server-type extended
[SwitchB-radius-scheme2] primary authentication 3.1.1.1
[SwitchB-radius-scheme2] key authentication 321123
[SwitchB-radius-scheme2] primary accounting 3.1.1.1
[SwitchB-radius-scheme2] key accounting 321123
[SwitchB-radius-scheme2] user-name-format without-domain
[SwitchB-radius-scheme2] quit
# Create an ISP domain
domain2
, reference
scheme2
for the authentication, authorization,
and accounting of LAN users, and specify
domain2
as the default ISP domain.
[SwitchB] domain domain2
[SwitchB-isp-domian2] authentication lan-access radius-scheme scheme2
[SwitchB-isp-domian2] authorization lan-access radius-scheme scheme2
[SwitchB-isp-domian2] accounting lan-access radius-scheme scheme2
[SwitchB-isp-domian2] quit
[SwitchB] domain default enable domain2
# Globally enable 802.1X, and enable it on GigabitEthernet 1/0/2 and GigabitEthernet 1/0/3
respectively.
[SwitchB] dot1x
[SwitchB] interface gigabitethernet 1/0/2
[SwitchB-GigabitEthernet1/0/2] dot1x
[SwitchB-GigabitEthernet1/0/2] quit
[SwitchB] interface gigabitethernet 1/0/3
[SwitchB-GigabitEthernet1/0/3] dot1x
[SwitchB-GigabitEthernet1/0/3] quit
4.
On the RADIUS server, configure the parameters related to Switch A and Switch B.
For more information, see the configuration guide of the RADIUS server.
Verifying the configuration
1.
Verify that Host A can join only the multicast group 224.1.1.1.
# Verify that the two multicast sources and hosts pass the 802.1X authentication. (Details not
shown.)
# Send multicast traffic from Source 1 and Source 2 to the multicast group 224.1.1.1 and
224.1.1.2, respectively. (Details not shown.)
# Send an IGMP report from Host A to join the multicast groups 224.1.1.1 and 224.1.1.2.
(Details not shown.)
# Display information about the IGMP snooping groups in VLAN 104 on Switch B.
[SwitchB] display igmp-snooping group vlan 100 verbose
Total 1 IP Group(s).
Total 1 IP Source(s).
Total 1 MAC Group(s).
Port flags: D-Dynamic port, S-Static port, C-Copy port, P-PIM port
Subvlan flags: R-Real VLAN, C-Copy VLAN
Vlan(id):100.
Total 1 IP Group(s).
Total 1 IP Source(s).
Total 1 MAC Group(s).
Router port(s):total 1 port(s).