127
2.
Configure a RADIUS scheme on the switch:
a.
From the navigation tree, select
Security
>
Authentication
>
RADIUS
.
b.
Add RADIUS scheme
portsec
.
c.
Configure the primary authentication server:
−
Set the IP address to
10.1.1.1
.
−
Set the authentication port number to
1812
.
−
Set the shared key to
name
.
−
Set the server state to
Active
.
d.
Configure the primary accounting server:
−
Set the IP address to
10.1.1.1
.
−
Set the accounting port number to
1813
.
−
Set the shared key to
name
.
−
Set the server state to
Active
.
e.
Configure the switch to not include domain names in the usernames sent to the RADIUS
server.
3.
Configure an ISP domain on the switch:
a.
From the navigation tree, select
Security
>
Authentication
>
ISP Domains
.
b.
Add ISP domain
portsec
, and set the domain state to
Active
.
c.
Set the access service to LAN access.
d.
Configure the ISP domain to use RADIUS scheme
portsec
for authentication, authorization,
and accounting of LAN users.
4.
Configure port security on the switch:
a.
From the navigation tree, select
Security
>
Access Control
>
Port Security
.
b.
Enable port security.
c.
On the advanced settings page for GigabitEthernet 1/0/1, set the port security mode to
userLoginWithOUI
.
d.
On the 802.1X tab of the advanced settings page for GigabitEthernet 1/0/1, set the 802.1X
mandatory domain to
portsec
.
e.
On the advanced settings page for port security, add five OUI values to the OUI list. The
OUI values include 1234-0100-1111, 1234-0200-1111, 1234-0300-1111, 1234-0400-1111,
and 1234-0500-1111.
5.
Configure the RADIUS server:
a.
Add a user account on the server. (Details not shown.)
b.
Configure the authentication, authorization, and accounting settings. (Details not shown.)
Verifying the configuration
1.
From the navigation tree, select
Security
>
Authentication
>
RADIUS
.
2.
Verify the configuration of RADIUS scheme
portsec
.
3.
From the navigation tree, select
Security
>
Authentication
>
ISP Domains
.
4.
Verify the configuration of ISP domain
portsec
.
5.
Use the configured user account to pass authentication.
6.
From the navigation tree, select
Security
>
Access Control
>
Port Security
.
7.
Verify that the number of online users is not
0
on GigabitEthernet 1/0/1.