当前位置:   article > 正文

华三交换机开设置802.1x和mac地址认证_802.1x配置mac认证

802.1x配置mac认证

 参考

  1. dot1x
  2. dot1x authentication-method eap
  3. dot1x timer reauth-period 300
  4. radius scheme leagsoft
  5. primary authentication 10.1.88.11
  6. key authentication simple leagsoft
  7. user-name-format without-domain
  8. q
  9. domain leagsoft
  10. authentication lan-access radius-scheme leagsoft none
  11. authorization lan-access radius-scheme leagsoft none
  12. accounting lan-access radius-scheme leagsoft none
  13. q
  14. mac-authentication
  15. mac-authentication domain leagsoft
  16. mac-authentication user-name-format mac-address with-hyphen lowercase
  17. domain default enable leagsoft
  18. dot1x ​ ​//开启全局的802.1x​​
  19. dot1x authentication-method eap //设备采用eap中继认证方式
  20. dot1x timer reauth-period 300 //设置重新认证定时器值为300
  21. radius scheme radius-test //创建radius方案
  22. radius-test primary authentication 192.168.1.88 ​ ​//配置主认证服务器192.168.1.88​​
  23. key authentication cipher Start123! //配置设备与radius服务器交互报文时的共享密钥为Start123!,要与radius服务器中的一致
  24. user-name-format without-domain //配置发送给radius服务器的用户名不携带域名
  25. domain radius-test //创建radius-test域
  26. authentication lan-access radius-scheme radius-test none //配置802.1x用户使用radius-test的radius方案进行认证
  27. authorization lan-access radius-scheme radius-test none //配置802.1x用户使用radius-test的radius方案进行授权
  28. accounting lan-access radius-scheme radius-test none //配置802.1x用户使用radius-test的radius方案进行计费
  29. domain default enable radius-test
  30. mac-authentication //开启全局mac地址认证
  31. mac-authentication domain radius-test //指定mac地址认证时使用的认证域
  32. mac-authentication user-name-format mac-address with-hyphen lowercase //配置mac地址认证时用户名格式,其中字母为小写,且不带连字符-
  33. interface GigabitEthernet1/0/7
  34. port access vlan 21
  35. stp edged-port
  36. dot1x ​ ​//端口上开启802.1x​​​
  37. undo dot1x handshake //关闭交换机接口握手功能
  38. dot1x mandatory-domain radius-test ​ ​//指定当前端口上接入的802.1x用户使用强制认证域​​
  39. radius-test mac-authentication //在端口上开启mac地址认证
  40. mac-authentication domain radius-test ​ ​//指定当前端口上接入的802.1x用户使用强制认证域​​
  41. radius-test mac-authentication timer auth-delay 10 ​​ ​//优先使用802.1x认证​​,如果认证不通过, 10秒后使用mac地址认证

附加:

  1. 开头
  2. #
  3. dot1x
  4. dot1x authentication-method eap
  5. #
  6. lldp global enable
  7. #
  8. password-recovery enable
  9. 接口
  10. interface GigabitEthernet1/0/1
  11. description caoningsheng
  12. port access vlan 1251
  13. dot1x
  14. undo dot1x handshake
  15. dot1x port-method portbased
  16. dot1x guest-vlan 421
  17. #
  18. interface GigabitEthernet1/0/2
  19. port access vlan 1123
  20. dot1x
  21. undo dot1x handshake
  22. dot1x port-method portbased
  23. dot1x guest-vlan 421
  24. #
  25. interface GigabitEthernet1/0/3
  26. port access vlan 1251
  27. dot1x
  28. undo dot1x handshake
  29. dot1x port-method portbased
  30. dot1x guest-vlan 421
  31. #
  32. interface GigabitEthernet1/0/4
  33. description zhanghailiang
  34. port access vlan 1231
  35. shutdown
  36. dot1x
  37. undo dot1x handshake
  38. dot1x port-method portbased
  39. dot1x guest-vlan 421
  40. 结尾
  41. #
  42. radius scheme system
  43. user-name-format without-domain
  44. #
  45. radius scheme uniaccess
  46. primary authentication 192.168.1.1
  47. secondary authentication 192.168.1.2
  48. key authentication simlp soft
  49. key accounting simlp soft
  50. user-name-format without-domain
  51. #
  52. domain system
  53. #
  54. domain uniaccess
  55. authentication lan-access radius-scheme uniaccess
  56. authorization lan-access radius-scheme uniaccess
  57. accounting lan-access radius-scheme uniaccess
  58. #
  59. domain default enable uniaccess

声明:本文内容由网友自发贡献,不代表【wpsshop博客】立场,版权归原作者所有,本站不承担相应法律责任。如您发现有侵权的内容,请联系我们。转载请注明出处:https://www.wpsshop.cn/w/喵喵爱编程/article/detail/853755
推荐阅读
相关标签
  

闽ICP备14008679号