125
Figure 43 Network diagram
Configuration procedure
1.
Configure IP addresses for the interfaces, as shown in
. (Details not shown.)
2.
Configure a RADIUS scheme on the switch:
a.
From the navigation tree, select
Security
>
Authentication
>
RADIUS
.
b.
Add RADIUS scheme
macauth
.
c.
Configure the primary authentication server:
−
Set the IP address to
10.1.1.1
.
−
Set the authentication port number to
1812
.
−
Set the shared key to
name
.
−
Set the server state to
Active
.
d.
Configure the primary accounting server:
−
Set the IP address to
10.1.1.1
.
−
Set the accounting port number to
1813
.
−
Set the shared key to
name
.
−
Set the server state to
Active
.
e.
Configure the switch to not include domain names in the usernames sent to the RADIUS
server.
3.
Configure an ISP domain on the switch:
a.
From the navigation tree, select
Security
>
Authentication
>
ISP Domains
.
b.
Add ISP domain
macauth
, and set the domain state to
Active
.
c.
Set the access service to LAN access.
d.
Configure the ISP domain to use RADIUS scheme
macauth
for authentication,
authorization, and accounting of LAN users.
4.
Configure MAC authentication on the switch:
a.
From the navigation tree, select
Security
>
Access Control
>
MAC Authentication
.
b.
Enable MAC authentication globally.
c.
Enable MAC authentication on GigabitEthernet 1/0/1.
d.
On the advanced settings page, configure the following parameters:
−
Set all users to use the same username and password.
−
Configure the username as
aaa
and password as
qaz123wdc
.
−
Specify the authentication domain as
macauth
.
5.
Configure the RADIUS server:
Internet
Switch
Host
192.168.1.2/24
GE1/0/1
Vlan-int2
192.168.1.1/24
RADIUS server
10.1.1.1/24
GE1/0/2
Vlan-int3
10.1.1.10/24