Contents
Configuring AAA ························································································································································· 1
Overview ············································································································································································ 1
RADIUS ······································································································································································ 2
HWTACACS ····························································································································································· 7
LDAP ·········································································································································································· 9
AAA for MPLS L3VPNs ········································································································································· 13
Protocols and standards ······································································································································· 13
RADIUS attributes ·················································································································································· 13
Configuring AAA schemes ············································································································································ 17
Configuring local users ········································································································································· 18
Configuring RADIUS schemes ······························································································································ 21
Configuring HWTACACS schemes ····················································································································· 29
Configuring LDAP schemes ·································································································································· 35
Configuration prerequisites ·································································································································· 39
Creating an ISP domain ······································································································································· 39
Displaying and maintaining AAA ································································································································ 43
Network requirements ··········································································································································· 43
Configuration procedure ······································································································································ 44
Network requirements ··········································································································································· 45
Configuration procedure ······································································································································ 45
Network requirements ··········································································································································· 46
Configuration procedure ······································································································································ 47
Network requirements ··········································································································································· 50
Configuration procedure ······································································································································ 50
Troubleshooting RADIUS ··············································································································································· 54
RADIUS authentication failure ······························································································································ 54
RADIUS packet delivery failure ···························································································································· 54
RADIUS accounting error ····································································································································· 55
Troubleshooting HWTACACS ······································································································································ 55
Troubleshooting LDAP ···················································································································································· 55
802.1X overview ······················································································································································· 57
802.1X architecture ······················································································································································· 57
802.1X-related protocols ·············································································································································· 58
Packet formats ························································································································································ 59
EAP over RADIUS ·················································································································································· 60
Initiating 802.1X authentication ··································································································································· 60
i