194
C
HAPTER
11: 802.1X C
ONFIGURATION
Figure 54
Networking when Switch 4500 Units are Applying RADIUS Authentication
Configuring AAA
AAA configuration includes:
■
Creating/deleting an ISP domain
■
Configuring relevant attributes of the ISP domain
■
Creating a local user
■
Setting attributes of the local user
■
Disconnecting a user by force
Among the above configuration tasks, creating ISP domain is compulsory,
otherwise the user attributes cannot be distinguished. The other tasks are
optional. You can configure them at requirements.
Creating/Deleting an ISP
Domain
What is Internet Service Provider (ISP) domain? To make it simple, ISP domain is a
group of users belonging to the same ISP. Generally, for a username in the
userid@isp-name format, taking [email protected] as an example, the
isp-name (that is,
3com163.net) following the @ is the ISP domain name. When
the Switch 4500 controls user access, as for an ISP user whose username is in
userid@isp-name format, the system will take userid part as username for
identification and take isp-name part as domain name.
The purpose of introducing ISP domain settings is to support the multi-ISP
application environment. In such an environment, one access device might access
users of different ISP. Because the attributes of ISP users, such as username and
password formats, and so on, may be different, it is necessary to differentiate
them through setting ISP domain. In the Switch 4500 units, ISP domain view, you
can configure a complete set of exclusive ISP domain attributes on a per-ISP
domain basis, which includes AAA policy ( RADIUS scheme applied etc.)
For the Switch 4500, each user belongs to an ISP domain. Up to 16 domains can
be configured in the system. If a user has not reported their ISP domain name, the
system will put them into the default domain.
Perform the following configurations in System View.
Internet
Internet
SW 5500
PC user1
PC user2
PC user3
PC user4
SW 5500
ISP1
ISP2
Authentication
Server
Accounting
Server
Authentication
Server
Accounting
Server1
Accounting
Server2
Internet
Содержание 400 Family
Страница 12: ......
Страница 16: ...14 ABOUT THIS GUIDE ...
Страница 58: ...56 CHAPTER 2 PORT OPERATION ...
Страница 68: ...66 CHAPTER 3 VLAN OPERATION ...
Страница 98: ...96 CHAPTER 5 NETWORK PROTOCOL OPERATION ...
Страница 124: ...122 CHAPTER 6 IP ROUTING PROTOCOL OPERATION ...
Страница 156: ...154 CHAPTER 8 ACL CONFIGURATION ...
Страница 218: ...216 CHAPTER 11 802 1X CONFIGURATION ...
Страница 298: ...296 CHAPTER 13 PASSWORD CONTROL CONFIGURATION OPERATIONS ...
Страница 336: ...334 APPENDIX B RADIUS SERVER AND RADIUS CLIENT SETUP ...