
Configuring 802.1x
267
primary-authentication/second-accounting server. The latter one acts as the
secondary-authentication/primary-accounting server. Set the encryption key as
“name” when the system exchanges packets with the authentication RADIUS
server and “money” when the system exchanges packets with the accounting
RADIUS server. Configure the system to retransmit packets to the RADIUS server if
no response is received within 5 seconds. Retransmit the packet no more than 5
times in all. Configure the system to transmit a real-time accounting packet to the
RADIUS server every 15 minutes. The system is instructed to transmit the user
name to the RADIUS server after removing the user domain name.
The user name of the local 802.1x access user is
localuser
and the password is
localpass
(input in plain text). The idle cut function is enabled.
Networking Diagram
Figure 67
Enabling 802.1x and RADIUS to Perform AAA on the User
Configuration Procedure
The following examples concern most of the AAA/RADIUS configuration
commands. For details, refer to the chapter AAA and RADIUS Protocol
Configuration.
The configurations of accessing user workstation and the RADIUS server are
omitted.
1
Enable the 802.1x performance on the specified port Ethernet 1/0/1.
[SW5500]
dot1x interface Ethernet 1/0/1
2
Set the access control mode. (This command could not be configured, when it is
configured as MAC-based by default.)
[SW5500]
dot1x port-method macbased interface Ethernet 1/0/1
3
Create the RADIUS scheme radius1 and enters its view.
[SW5500]
radius scheme radius1
4
Set IP address of the primary authentication/accounting RADIUS servers.
[SW5500-radius-radius1]
primary authentication 10.11.1.1
[SW5500-radius-radius1]
primary accounting 10.11.1.2
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
E1/0/1
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
User
Содержание SuperStack 4
Страница 6: ...18 ABOUT THIS GUIDE ...
Страница 13: ...Logging in to the Switch 25 Figure 3 Setting up a New Connection Figure 4 Configuring the Port for Connection ...
Страница 34: ...46 CHAPTER 1 GETTING STARTED ...
Страница 62: ...74 CHAPTER 3 VLAN OPERATION ...
Страница 69: ...PoE Configuration 81 ...
Страница 70: ...82 CHAPTER 4 POWER OVER ETHERNET POE CONFIGURATION ...
Страница 98: ...110 CHAPTER 5 NETWORK PROTOCOL OPERATION ...
Страница 220: ...232 CHAPTER 8 ACL CONFIGURATION ...
Страница 408: ...420 CHAPTER B RADIUS SERVER AND RADIUS CLIENT SETUP ...
Страница 432: ...444 APPENDIX D 3COM XRN ...