93
EAD fast deployment configuration example
Network requirements
As shown in
, the hosts on the intranet 192.168.1.0/24 are attached to port GigabitEthernet
1/0/1 of the network access device, and they use DHCP to obtain IP addresses.
Deploy EAD solution for the intranet so that all hosts must pass 802.1X authentication to access the
network.
To allow all intranet users to install and update the 802.1X client program from a web server, configure
the following:
•
Allow unauthenticated users to access the segment of 192.168.2.0/24 and to obtain IP addresses
on the segment of 192.168.1.0/24 through DHCP.
•
Redirect unauthenticated users to a preconfigured web page when the users use a web browser to
access any external network except 192.168.2.0/24. The web page allows users to download the
802.1X client program.
•
Allow authenticated 802.1X users to access the network.
Figure 36
Network diagram for EAD fast deployment
GE1/0/2
10.1.1.10/24
GE1/0/1
Free IP:
WEB server
192.168.2.3/24
Internet
192.168.1.0/24
Vlan-int 2
192.168.1.1/24
192.168.2.0/24
GE1/0/3
192.168.2.1/24
DHCP server
192.168.2.1/24
Authentication servers
10.1.1.1/10.1.1.2
Device
In addition to the configuration on the access device, complete the following tasks:
•
Configure the DHCP server so that the host can obtain an IP address on the segment of
192.168.1.0/24.
•
Configure the web server so that users can log in to the web page to download 802.1X clients.
•
Configure the authentication server to provide authentication, authorization, and accounting
services.
Configuration procedure
1.
Configure an IP address for each interface. (Details not shown)
2.
Configure DHCP relay.
# Enable DHCP.
Содержание A5830 Series
Страница 207: ...199 Figure 62 SFTP client interface ...