data:image/s3,"s3://crabby-images/e8dd3/e8dd3fcf704be5cf6dc2e5cf58da6c422be43b79" alt="Huawei AR1200-S Series Configuration Manual Download Page 134"
Data Preparation
To complete the configuration, you need the following data:
l
IP address 192.168.2.30 and port number 1812 of the RADIUS authentication server
l
RADIUS server key
dot1x-isp
and retransmission count 2
l
AAA authentication scheme
scheme1
l
RADIUS server template
temp1
l
Domain
isp1
NOTE
In this example, only the Router configuration is provided, and the RADIUS server configuration is not
mentioned here.
Procedure
Step 1
Configure a RADIUS server template.
# Configure a RADIUS server template
temp1
.
[Huawei]
radius-server template temp1
# Configure the IP address and port number of the primary RADIUS authentication server.
[Huawei-radius-temp1]
radius-server authentication 192.168.2.30 1812
# Configure the key and retransmission count of the RADIUS server.
[Huawei-radius-temp1]
radius-server shared-key cipher dot1x-isp
[Huawei-radius-temp1]
radius-server retransmit 2
[Huawei-radius-temp1]
quit
Step 2
Create an authentication scheme
scheme1
and set the authentication mode to RADIUS
authentication.
[Huawei]
aaa
[Huawei-aaa]
authentication-scheme scheme1
[Huawei-aaa-scheme1]
authentication-mode radius
[Huawei-aaa-scheme1]
quit
Step 3
Create a domain
isp1
and bind the authentication scheme and RADIUS server template to the
domain.
[Huawei-aaa]
domain isp1
[Huawei-aaa-domain-isp1]
authentication-scheme scheme1
[Huawei-aaa-domain-isp1]
radius-server temp1
[Huawei-aaa-domain-isp1]
quit
[Huawei-aaa]
quit
Step 4
Configure 802.1x authentication.
# Enable 802.1x authentication globally and on an interface.
[Huawei]
dot1x enable
[Huawei]
interface ethernet 2/0/0
[Huawei-Ethernet2/0/0]
dot1x enable
[Huawei-Ethernet2/0/0]
quit
# Configure a guest VLAN.
[Huawei]
vlan batch 10
[Huawei]
interface ethernet 2/0/0
[Huawei-Ethernet2/0/0]
dot1x guest-vlan 10
[Huawei-Ethernet2/0/0]
quit
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
5 NAC Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
120