X Configuration Example - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

1744
C
92: 802.1
HAPTER
802.1x Configuration
Example
C
X
ONFIGURATION
Network requirements
The access control method of macbased is required on the port to control
supplicants.
All supplicants belong to default domain aabbcc.net, which can accommodate
up to 30 users. RADIUS authentication is performed at first, and then local
authentication when no response from the RADIUS server is received. If the
RADIUS accounting fails, the authenticator gets users offline.
A server group with two RADIUS servers is connected to the router. The IP
addresses of the servers are 10.1.1.1 and 10.1.1.2 respectively. Use the former
as the primary authentication/secondary accounting server, and the latter as
the secondary authentication/primary accounting server.
Set the shared key for the router to exchange packets with the authentication
server as name, and that for the router to exchange packets with the
accounting server as money.
Specify the router to try up to five times at an interval of 5 seconds in
transmitting a packet to the RADIUS server until it receives a response from the
server, and to send real time accounting packets to the accounting server every
15 minutes.
Specify the router to remove the domain name from the username before
passing the username to the RADIUS server.
Set the username of the 802.1x user as localuser and the password as localpass
and specify to use clear text mode. Enable the idle cut function to get the user
offline whenever the user remains idle for over 20 minutes.
Network diagram
Figure 507 Network diagram for 802.1x configuration
Supplicant
Configuration procedure
n
The following configuration procedure covers most AAA/RADIUS configuration
commands for the authenticator, while configuration on the supplicant and
RADIUS server are omitted. For information about AAA/RADIUS configuration
commands, refer to
# Configure the IP addresses for each interface. (Omitted)
Authentication servers
(RADIUS server cluster )
10.1.1.1
10.1.1.2
Eth 1 /1
Authenticator
1.1 .1. 1/ 24
Router
"AAA/RADIUS/HWTACACS Configuration" on page
Internet
1751.

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents