
5.6 Configuration Examples
This section provides several NAC configuration examples.
5.6.1 Example for Configuring 802.1x Authentication
After 802.1x authentication is configured, a user that is not authenticated can access limited
network resources. This ensures network security.
Networking Requirements
As shown in
, users access the Internet using the Router. To ensure network security,
users must be authenticated before accessing the Internet. Users that are authenticated can access
the Internet, but users that fail to be authenticated can access only resources in VLAN 10.
Figure 5-2
Networking diagram of 802.1x authentication
Router
PC
RADIUS server
Printer
Eth 2/0/0
GE0/0/1
Eth 2/0/1
Internet
192.168.2.10/24
192.168.2.30/24
Configuration Roadmap
The configuration roadmap is as follows:
1.
Configure AAA authentication. User names and passwords are sent to the RADIUS server
for authentication.
2.
Configure 802.1x authentication to authenticate users on Ethernet2/0/0.
3.
Configure a guest VLAN so that users that fail to be authenticated can access resources in
VLAN 10.
4.
Configure MAC address bypass authentication to authenticate printers connected to
Ethernet2/0/1.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
5 NAC Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
119