1-26
[Device-radius-2000] primary accounting 10.11.1.1 1813
[Device-radius-2000] key authentication abc
[Device-radius-2000] key accounting abc
[Device-radius-2000] user-name-format without-domain
[Device-radius-2000] quit
# Configure authentication domain
system
and specify to use RADIUS scheme 2000 for users of the
domain.
[Device] domain system
[Device-isp-system] authentication default radius-scheme 2000
[Device-isp-system] authorization default radius-scheme 2000
[Device-isp-system] accounting default radius-scheme 2000
[Device-isp-system] quit
# Enable 802.1X globally.
[Device] dot1x
# Enable 802.1X for port GigabitEthernet 2/0/2.
[Device] interface GigabitEthernet2/0/2
[Device-GigabitEthernet2/0/2] dot1x
# Set the port access control method to
portbased
.
[Device-GigabitEthernet2/0/2] dot1x port-method portbased
# Set the port authorization mode to
auto
.
[Device-GigabitEthernet2/0/2] dot1x port-control auto
[Device-GigabitEthernet2/0/2] quit
# Create VLAN 10.
[Device] vlan 10
[Device-vlan10] quit
# Specify port GigabitEthernet 2/0/2 to use VLAN 10 as its guest VLAN.
[Device] dot1x guest-vlan 10 interface gigabitethernet 2/0/2
You can use the
display current-configuration
or
display interface gigabitethernet 2/0/2
command
to view your configuration. You can also use the
display vlan 10
command to verify whether the
configured guest VLAN functions normally when the device sends authentication triggering packets
(EAP-Request/Identity) for more than the specified number of times in the following cases:
z
When no users log in.
z
When a user goes offline.
After a user passes the authentication successfully, you can use the
display interface gigabitethernet
2/0
/
2
command to verity that port GigabitEthernet 2/0/2 has been added to the assigned VLAN 5.
ACL Assignment Configuration Example
Network requirements
As shown in
Figure 1-14
, a host is connected to port GigabitEthernet 2/0/1 of the device and must pass
802.1X authentication to access the Internet.
z
Configure the RADIUS server to assign ACL 3000.
z
Enable 802.1X authentication on port GigabitEthernet 2/0/1 of the device, and configure ACL 3000.
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...