Configuration Guide
802.1x Configuration
Ruijie(config)#
aaa group server radius
auth-ll
Ruijie(config-gs-radius)#
server
192.168.4.1
Ruijie(config-gs-radius)#
server
192.168.4.12
Ruijie(config-gs-radius)#
end
Ruijie#
Configuring and Managing Online Users
Ruijie’s devices provide management for authenticated users via SNMP. The administrator can view the information of the
authorized users via SNMP, and forcedly log off a user. The user forcedly logged off must pass the authentication again
before it can use network resources.
This function calls for no configuration on the device.
Implementing User-IP Binding
With our clients and by correctly configuring the Radius Server, you can implement unique user-IP binding. A user must
undergo authentication by using the IP address allocated by the administrator. Otherwise, authentication will fail.
For this function, you do not need to configure the switch. The user needs to use our client and the administrator needs to
configure the Radius Server.
Port-based Traffic Charging
In addition to the duration-
based billing, Ruijie’s network devices provide the traffic-based billing function in case each port
of the equipment has only one user access.
This function calls for no configuration on the device but need the support of the Radius server.
Implementing Automatic Switching and Control of VLAN
To implement the auto-switching of the dynamic VLAN, the user VLAN shall be assigned and configured by the remote
RADIUS server. The remote RADIUS server encapsulates the VLAN assignment information through the defined RADIUS
attributes. After receiving those information and the user authentication, the access device automatically adds the port
where the user is to the VLAN assigned by the RADIUS server. It is unnecessary of the manual configurations for the
administrator.
You shall use the
show dot1x summary
command to on the access device to view the actual VLAN where the user is.
Use the
show dot1x user id
command to view the VLAN assigned by the RADIUS server.
The access device is able to receive the VLAN assigned by the RADIUS server in two ways of the extension RADIUS
attributes and the standard RADIUS attributes.
The RADIUS server assigns the VLAN to the access device using the standard-extension attributes. The server
encapsulates the extension attributes into the No.26 RADIUS standard attributes. The extension manufacturing ID is in
hex 0x00001311. By default, the extension attribute type is 4, you can use the
radius attribute 4 vendor-type
type
command to set the extension attribute type number to assign the VLAN. For the configuration command, see
RADIUS
Configuration
.
Summary of Contents for RG-S2900G-E Series
Page 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Page 91: ...Configuration Guide Configuring PoE Configuration ...
Page 133: ...Configuration Guide EEE Configuration ...
Page 319: ...Configuration Guide QinQ Configuration ...
Page 408: ......
Page 409: ...IP Routing Configuration 1 Static Route Configuration ...
Page 412: ......
Page 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Page 757: ......
Page 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Page 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Page 901: ...Configuration Guide ERSPAN Configuration ...
Page 902: ...Web based Configuration 1 Web based Configuration ...