Chapter 7 Service Configuration
F
IGURE
75 A
CCESS
A
UTHENTICATION
C
ONFIGURATION
E
XAMPLE
1. configure dot1x commands
zte(cfg)#set port 2 security enable
zte(cfg)#config nas
zte(cfg-nas)#aaa port 2 dot1x enable
zte(cfg-nas)#aaa port 2 keepalive enable
zte(cfg-nas)#aaa port 2 accounting enable
2. configure radius commands
zte(zte)#config nas
zte(cfg-nas)#radius isp zte enable
zte(cfg-nas)#radius isp zte defaultisp enable
zte(cfg-nas)#radius isp zte sharedsecret isam
zte(cfg-nas)#radius isp zte client 192.168.20.20
zte(cfg-nas)#radius isp zte add accounting 192.168.20.199 1812
zte(cfg-nas)#radius isp zte add authentication 192.168.20.199 1813
3. Enable radius client software on PC and input correct username
and password. Then the authentication request is launched.
When the authentication request succeeds, view the user in-
formation by using the command show client.
zte(cfg)#show client
MaxClients
: 256
HistoryAccessClientsTotal : 1
OnlineClients: 1
HistoryFailureClientsTotal: 0
Index UserName Authorized PortId VlanId
MacAddress ElapsedTime
----- --------- ---------- ------ ------
------------
------------
0
zhouzhou
yes
2
1
00.0a.eb.93.10.23 0:0:0:7
Caution:
Disable the security proxy such as Sygate before the user PC send-
ing authentication request.
Confidential and Proprietary Information of ZTE CORPORATION
181