ZXR10 5900/5200 Series User Manual (Basic Configuration Volume)
a logical authentication channel for each user and other users
cannot use the logical channel after the port is enabled.
3. Authentication server is usually a RADIUS server. In authen-
tication server user-related information is stored such as the
VLAN where the user locates, CAR parameter, priority and ac-
cess control list of the user. Once the user passes authen-
tication, the authentication server delivers user-related infor-
mation to the authentication system which creates a dynamic
access control list. The above parameters are used to mea-
sure subsequent traffic of the user. Authentication server and
RADIUS server communicate with each other through the RA-
DIUS protocol.
Configuring DOT1X
Configuring AAA
1. To create an AAA control entry, use the following command.
Command
Function
ZXR10(config-nas)#
create aaa
<
rule-id
>[
port
<
port-name
>][
vlan
<
vlan-id
>]
This creates an AAA control
entry.
2. To clear an AAA control entry, use the following command.
Command
Function
ZXR10(config-nas)#
clear aaa
<
rule-id
>
This clears an AAA control entry.
3. To enable/disable dot1x authentication or trunk, use the fol-
lowing command.
Command
Function
ZXR10(config-nas)#
aaa
<
rule-id
>
control
{
dot1x
|
dot1x
-relay
}{
enable
|
disable
}
This enables/disables dot1x
authentication or trunk.
4. To select an authentication mode, use the following command.
Command
Function
ZXR10(config-nas)#
aaa
<
rule-id
>
authentication
{
local
|
radius
}
This selects an authentication
mode.
5. To select an authentication protocol, use the following com-
mand.
130
Confidential and Proprietary Information of ZTE CORPORATION