CHAPTER 10. Layer-2 Switching
80
© SAMSUNG Electronics Co., Ltd.
Configuring 802.1x
IEEE 802.1x restricts unauthenticated devices from connecting to the router,
typically in a VLAN/Bridge environment. Only authenticated traffic is
allowed through the Ubigate iBG3026.
In the configuration example, the RADIUS Server keeps the Client
information, validating the identity of the client and updating the router about
the client authentication status. The router is the physical path between the two
clients and the RADIUS server. The Ubigate iBG3026 relays information to
the Server and then back to each client.
To configure 802.1x authentication, enable authentication on ports Ethernet
1/1 and Ethernet 2/1, then specify the RADIUS Server IP address and port.
Figure 10.1 Configuring 802.1x Security
Router# configure terminal
Router/configure# bridge 1 protocol mstp
Router/configure# vlan database
Router/configure/vlan/database# vlan 2 bridge 1
Router/configure/vlan/database# exit
Router/configure# dot1x system-auth-ctrl
Router/configure# interface ethernet 1/0
Router/configure/interface/ethernet(1/0)# switchport
Router/configure/interface/ethernet(1/0)# bridge-group 1
Router/configure/interface/ethernet(1/0)# switchport
access vlan 2
Router/configure/interface/ethernet(1/0)# dot1x port-control
auto
Router/configure/interface/ethernet(1/0)# exit
Router/configure# interface ethernet 1/1
Router/configure/interface/ethernet(1/1)# switchport
Router/configure/interface/ethernet(1/1)# bridge-group 1
RADIUS
Server
iBG3026
Client
Certificate
Server
eth1
eth0
eth2
192.126.12.1
Summary of Contents for Ubigate iBG3026
Page 1: ......
Page 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 32: ...TABLE OF CONTENTS XXX SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 34: ......
Page 64: ...CHAPTER 4 System Logging 30 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 72: ......
Page 94: ...CHAPTER 7 WAN Interfaces 58 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 110: ......
Page 156: ...CHAPTER 15 BGP 118 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 178: ...CHAPTER 17 VRRP 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 262: ......
Page 288: ...CHAPTER 23 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 346: ......
Page 706: ...CHAPTER 36 Management 664 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 718: ...EQBD 000026 Ed 00 ...