202
C
HAPTER
11: 802.1X C
ONFIGURATION
2
Add local access user.
a
Set the user name and password.
[SW4500]
local-user 00e0fc010101
[SW4500-luser-00e0fc010101]
password simple 00e0fc010101
b
Set the service type of the user to lan-access.
[SW4500-luser-00e0fc010101]
service-type lan-access
3
Enable the MAC address authentication globally.
[SW4500]
mac-authentication
4
Configure the ISP domain used by the user.
[SW4500]
mac-authentication domain 3com163.net
For the configuration of the domain 3com163.net, see
“802.1X Configuration
Example”
on
page 196
.
AAA and RADIUS
Protocol
Configuration
Authentication, Authorization and Accounting (AAA) provide a uniform
framework used for configuring these three security functions to implement the
network security management.
The network security mentioned here refers to access control and it includes:
■
Which user can access the network server?
■
Which service can the authorized user enjoy?
■
How to keep accounts for the user who is using the network resource?
Accordingly, AAA provides the following services:
■
Authentication: authenticates if the user can access the network server.
■
Authorization: authorizes the user with specified services.
■
Accounting: traces network resources consumed by the user.
RADIUS Protocol
Overview
As mentioned above, AAA is a management framework, so it can be implemented
by some protocols. RADIUS is such a protocol that is frequently used.
What is RADIUS?
Remote Authentication Dial-In User Service, RADIUS for short, is a type of
distributed information switching protocol in Client/Server architecture. RADIUS
can prevent the network from interruption of unauthorized access and it is often
used in the network environments requiring both high security and remote user
access. For example, it is often used for managing a large number of scattering
dial-in users who use serial ports and modems. RADIUS system is the important
auxiliary part of Network Access Server (NAS).
After RADIUS system is started, if the user wants to have the right to access other
networks or consume some network resources through connection to NAS (dial-in
access server in PSTN environment or a Switch with the access function in an
Ethernet environment), NAS, namely RADIUS client end, will transmit user AAA
request to the RADIUS server. A RADIUS server has a user database recording all
the information of user authentication and network service access. When
Содержание Switch 4500 26-Port
Страница 16: ...14 ABOUT THIS GUIDE...
Страница 58: ...56 CHAPTER 2 PORT OPERATION...
Страница 104: ...102 CHAPTER 5 NETWORK PROTOCOL OPERATION...
Страница 130: ...128 CHAPTER 6 IP ROUTING PROTOCOL OPERATION...
Страница 154: ...152 CHAPTER 7 ACL CONFIGURATION...
Страница 228: ...226 CHAPTER 11 802 1X CONFIGURATION...
Страница 250: ...248 CHAPTER 14 DEVICE MANAGEMENT...
Страница 280: ...278 CHAPTER 15 SYSTEM MAINTENANCE AND DEBUGGING...
Страница 312: ...310 CHAPTER 18 NTP CONFIGURATION...
Страница 340: ...338 CHAPTER 19 SSH TERMINAL SERVICES...
Страница 350: ...348 CHAPTER 20 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Страница 388: ...386 APPENDIX B RADIUS SERVER AND RADIUS CLIENT SETUP...