Configuring 802.1X
197
RADIUS server every 15 minutes. The system is instructed to transmit the user
name to the RADIUS server after removing the user domain name.
The user name of the local 802.1X access user is
localuser
and the password is
localpass
(input in plain text). The idle cut function is enabled.
Networking Diagram
Figure 56
Enabling 802.1X and RADIUS to Perform AAA on the User
Configuration Procedure
The following examples concern most of the AAA/RADIUS configuration
commands. For details, refer to the chapter AAA and RADIUS Protocol
Configuration.
The configurations of accessing user workstation and the RADIUS server are
omitted.
1
Enable the 802.1X performance on the specified port Ethernet 1/0/1.
[4500]
dot1x interface Ethernet 1/0/1
2
Set the access control mode. (This command could not be configured, when it is
configured as MAC-based by default.)
[4500]
dot1x port-method macbased interface Ethernet 1/0/1
3
Create the RADIUS scheme radius1 and enters its view.
[4500]
radius scheme radius1
4
Set IP address of the primary authentication/accounting RADIUS servers.
[4500-radius-radius1]
primary authentication 10.11.1.1
[4500-radius-radius1]
primary accounting 10.11.1.2
5
Set the IP address of the second authentication/accounting RADIUS servers.
[4500-radius-radius1]
secondary authentication 10.11.1.2
[4500-radius-radius1]
secondary accounting 10.11.1.1
6
Set the encryption key when the system exchanges packets with the
authentication RADIUS server.
[4500-radius-radius1]
key authentication name
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
E1/0/1
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
User
Содержание Switch 4500 26-Port
Страница 16: ...14 ABOUT THIS GUIDE...
Страница 58: ...56 CHAPTER 2 PORT OPERATION...
Страница 104: ...102 CHAPTER 5 NETWORK PROTOCOL OPERATION...
Страница 130: ...128 CHAPTER 6 IP ROUTING PROTOCOL OPERATION...
Страница 154: ...152 CHAPTER 7 ACL CONFIGURATION...
Страница 228: ...226 CHAPTER 11 802 1X CONFIGURATION...
Страница 250: ...248 CHAPTER 14 DEVICE MANAGEMENT...
Страница 280: ...278 CHAPTER 15 SYSTEM MAINTENANCE AND DEBUGGING...
Страница 312: ...310 CHAPTER 18 NTP CONFIGURATION...
Страница 340: ...338 CHAPTER 19 SSH TERMINAL SERVICES...
Страница 350: ...348 CHAPTER 20 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Страница 388: ...386 APPENDIX B RADIUS SERVER AND RADIUS CLIENT SETUP...