Configuration Example
163
and the authenticating RADIUS server to be name, and money for interaction
between the switch and the counting RADIUS. Configure the waiting period for
the switch to resend packets to the RADIUS server to be 5 seconds, that is, if after
5 seconds the RADIUS still has not sent any responses back, the switch will resend
packets. Configure the number of times that a switch resends packets to the
RADIUS server to be 5. Configure the switch to send real-time counting packets to
the RADIUS server every 15 minutes with the domain names removed from the
user name beforehand.
■
The user name and password for local 802.1x authentication are localuser and
localpass (in plain text) respectively. The idle disconnecting function is enabled.
Network diagram
Figure 53
Network diagram for AAA configuration with 802.1x and RADIUS enabled
Configuration procedure
Following configuration covers the major AAA/RADIUS configuration commands. You
can refer to AAA&RADIUS Operation Manual for the information about these
commands. Configuration on the client and the RADIUS servers is omitted.
1
Enable 802.1x globally.
<S4200G>
system-view
System View: return to User View with Ctrl+Z.
[4200G]
dot1x
2
Enable 802.1x for GigabitEthernet1/0/1 port.
[4200G]
dot1x interface GigabitEthernet 1/0/1
3
Set the access control method to be MAC-address-based (can be omitted as
MAC-address-based is the default configuration).
[4200G]
dot1x port-method macbased interface GigabitEthernet 1/0/1
4
Create a RADIUS scheme named radius1 and enter RADIUS scheme view.
[4200G]
radius scheme radius1
5
Assign IP addresses to the primary authentication and accounting RADIUS servers.
[4200G-radius-radius1]
primary authentication 10.11.1.1
[4200G-radius-radius1]
primary accounting 10.11.1.2
Содержание 4200G 12-Port
Страница 10: ...8 CONTENTS...
Страница 14: ...4 ABOUT THIS GUIDE...
Страница 46: ...32 CHAPTER 5 LOGGING IN THROUGH WEB BASED NETWORK MANAGEMENT SYSTEM...
Страница 48: ...34 CHAPTER 6 LOGGING IN THROUGH NMS...
Страница 60: ...46 CHAPTER 9 VLAN CONFIGURATION...
Страница 64: ...50 CHAPTER 10 MANAGEMENT VLAN CONFIGURATION...
Страница 80: ...66 CHAPTER 13 GVRP CONFIGURATION...
Страница 98: ...84 CHAPTER 15 LINK AGGREGATION CONFIGURATION...
Страница 112: ...98 CHAPTER 18 MAC ADDRESS TABLE MANAGEMENT...
Страница 126: ...112 CHAPTER 19 LOGGING IN THROUGH TELNET...
Страница 162: ...148 CHAPTER 20 MSTP CONFIGURATION...
Страница 274: ...260 CHAPTER 29 IGMP SNOOPING CONFIGURATION...
Страница 276: ...262 CHAPTER 30 ROUTING PORT JOIN TO MULTICAST GROUP CONFIGURATION...
Страница 298: ...284 CHAPTER 33 SNMP CONFIGURATION...
Страница 304: ...290 CHAPTER 34 RMON CONFIGURATION...
Страница 338: ...324 CHAPTER 36 SSH TERMINAL SERVICES...
Страница 356: ...342 CHAPTER 38 FTP AND TFTP CONFIGURATION...
Страница 365: ...Information Center Configuration Example 351 S4200G terminal logging...
Страница 366: ...352 CHAPTER 39 INFORMATION CENTER...
Страница 378: ...364 CHAPTER 40 BOOTROM AND HOST SOFTWARE LOADING...
Страница 384: ...370 CHAPTER 41 Basic System Configuration and Debugging...
Страница 388: ...374 CHAPTER 43 NETWORK CONNECTIVITY TEST...
Страница 406: ...392 CHAPTER 45 CONFIGURATION OF NEWLY ADDED CLUSTER FUNCTIONS...
Страница 422: ...408 CHAPTER 48 UDP HELPER CONFIGURATION...