
206
2.
Set the 802.1X authentication method to CHAP. By default, the authentication method for
802.1X is CHAP.
[Device] dot1x authentication-method chap
3.
Configure port security:
# Enable port security.
[Device] port-security enable
# Add five OUI values. (You can add up to 16 OUI values. The port permits only one user
matching one of the OUIs to pass authentication.)
[Device] port-security oui index 1 mac-address 1234-0100-1111
[Device] port-security oui index 2 mac-address 1234-0200-1111
[Device] port-security oui index 3 mac-address 1234-0300-1111
[Device] port-security oui index 4 mac-address 1234-0400-1111
[Device] port-security oui index 5 mac-address 1234-0500-1111
# Set the port security mode to userLoginWithOUI.
[Device] interface gigabitethernet 1/0/1
[Device-GigabitEthernet1/0/1] port-security port-mode userlogin-withoui
[Device-GigabitEthernet1/0/1] quit
Verifying the configuration
# Verify the RADIUS scheme configuration.
[Device] display radius scheme radsun
RADIUS Scheme Name : radsun
Index : 0
Primary Auth Server:
Host name: Not configured
IP : 192.168.1.2 Port: 1812
State: Active
VPN : Not configured
Primary Acct Server:
Host name: Not configured
IP : 192.168.1.3 Port: 1813
State: Active
VPN : Not configured
Second Auth Server:
Host name: Not configured
IP : 192.168.1.3 Port: 1812
State: Active
VPN : Not configured
Second Acct Server:
Host name: Not configured
IP : 192.168.1.2 Port: 1813
State: Active
VPN : Not configured
Accounting-On function : Disabled
retransmission times : 50
retransmission interval(seconds) : 3
Timeout Interval(seconds) : 5
Retransmission Times : 5
Содержание 10500 series
Страница 326: ...312 No duration limit for this SA ...