Operation Manual - Security
Quidway S3000-EI Series Ethernet Switches
Chapter 1 802.1x Configuration
Huawei Technologies Proprietary
1-16
A server group, consisting of two RADIUS servers at 10.11.1.1 and 10.11.1.2
respectively, is connected to the switch. The former one acts as the
primary-authentication/secondary-accounting server. The latter one acts as the
primary-accounting server. Set the encryption key as “name” when the system
exchanges packets with the authentication RADIUS server and “money” when the
system exchanges packets with the accounting RADIUS server. Configure the system
to retransmit packets to the RADIUS server if no response received in 5 seconds.
Retransmit the packet no more than 5 times in all. Configure the system to transmit a
real-time accounting packet to the RADIUS server every 15 minutes. The system is
instructed to transmit the user name to the RADIUS server after removing the user
domain name.
The user name of the local 802.1x access user is localuser and the password is
localpass (input in plain text). The idle cut function is enabled.
II. Networking diagram
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
E0/1
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
Supplicant
Authentication Servers
(RADIUS Server Cluster
IP Address: 10.11.1.1
10.11.1.2)
Internet
Authenticator
Switch
Figure 1-2
Enabling 802.1x and RADIUS to perform AAA on the supplicant
III. Configuration procedure
Note:
The following examples concern most of the AAA/RADIUS configuration commands.
For details, refer to the chapter AAA and RADIUS Protocol Configuration.
The configurations of accessing user workstation and the RADIUS server are omitted.
# Enable the 802.1x performance on the specified port Ethernet 0/1.
[Quidway] dot1x interface Ethernet 0/1
Содержание Quidway S3000-EI Series
Страница 49: ...Huawei Technologies Proprietary HUAWEI Quidway S3000 EI Series Ethernet Switches Operation Manual Port ...
Страница 66: ...Huawei Technologies Proprietary HUAWEI Quidway S3000 EI Series Ethernet Switches Operation Manual VLAN ...
Страница 90: ...Huawei Technologies Proprietary HUAWEI Quidway S3000 EI Series Ethernet Switches Operation Manual Multicast ...
Страница 113: ...Huawei Technologies Proprietary HUAWEI Quidway S3000 EI Series Ethernet Switches Operation Manual QoS ACL ...
Страница 148: ...Huawei Technologies Proprietary HUAWEI Quidway S3000 EI Series Ethernet Switches Operation Manual Integrated Management ...
Страница 178: ...Huawei Technologies Proprietary HUAWEI Quidway S3000 EI Series Ethernet Switches Operation Manual STP ...
Страница 207: ...Huawei Technologies Proprietary HUAWEI Quidway S3000 EI Series Ethernet Switches Operation Manual Security ...
Страница 255: ...Huawei Technologies Proprietary HUAWEI Quidway S3000 EI Series Ethernet Switches Operation Manual Network Protocol ...
Страница 277: ...Huawei Technologies Proprietary HUAWEI Quidway S3000 EI Series Ethernet Switches Operation Manual System Management ...
Страница 377: ...Huawei Technologies Proprietary HUAWEI Quidway S3000 EI Series Ethernet Switches Operation Manual Remote Power feeding ...
Страница 389: ...Huawei Technologies Proprietary HUAWEI Quidway S3000 EI Series Ethernet Switches Operation Manual Appendix ...