Enabling Peap-Ms-Chap-V2 Authentication - 3Com 3CRWX120695A, 3CRWX440095A Configuration Manual

Wireless lan switch and controller
Table of Contents

Advertisement

338
C
13: C
HAPTER
ONFIGURING
Enabling
PEAP-MS-CHAP-V2
Authentication
WX1200# set authentication dot1x ssid thiscorp * peap-mschapv2 local
AAA
N
FOR
ETWORK
4 Save the configuration:
WX1200# save config
success: configuration saved.
(For information about setting up RADIUS servers for remote
authentication, see Chapter 14, "Configuring Communication with
RADIUS," on page 343.)
The following example illustrates how to enable local PEAP-MS-CHAP-V2
authentication for all 802.1X network users. This example includes local
usernames, passwords, and membership in a VLAN. This example
includes one username and an optional attribute for session-timeout in
seconds. Because the WX switch requires a certificate for authentication,
configuration of a self-signed certificate is shown.
1 To set authentication for all 802.1X users of SSID thiscorp, type the
following command:
2 To add user Natasha to the local database on the WX switch, type the
following command:
WX1200# set user Natasha password moon
3 To assign Natasha to a VLAN named red, type the following command:
WX1200# set user Natasha attr vlan-name red
4 To assign Natasha a session timeout value of 1200 seconds, type the
following command:
WX1200# set user Natasha attr session-timeout 1200
5 To generate a public-private key pair and a self-signed EAP certificate,
type the following commands:
WX1200# crypto generate key eap 1024
key pair generated
WX1200# crypto generate self-signed eap
Country Name: US
State Name: CA
Locality Name: Campus1
Organizational Name: Example
Organizational Unit: IT
Common Name: WX33
Email Address: admin@example.com
Unstructured Name: wiring closet 22
U
SERS

Advertisement

Table of Contents
loading

Table of Contents