Verifying The Configuration; With Acl Assignment Configuration Example; Network Requirements; Configuration Procedure - HPE FlexNetwork MSR Series Comware 5 Security Configuration Manual

Table of Contents

Advertisement

Verifying the configuration

Use the display dot1x interface ethernet 1/2 command to verify the 802.1X guest VLAN
configuration on Ethernet 1/2. If no user passes authentication on the port within a specific period of
time, use the display vlan 10 command to verify whether Ethernet 1/2 is assigned to VLAN 10.
After a user passes authentication, you can use the display interface ethernet 1/2 command to
verity that port Ethernet 1/2 has been added to VLAN 5.
802.1X with ACL assignment configuration
example

Network requirements

As shown in
device.
Perform 802.1X authentication on the port. Use the RADIUS server at 10.1.1.1 as the authentication
and authorization server and the RADIUS server at 10.1.1.2 as the accounting server. Assign an
ACL to Ethernet 1/1 to deny the access of 802.1X users to the FTP server at 10.0.0.1/24 on
weekdays during business hours from 8:00 to 18:00.
Figure 45 Network diagram

Configuration procedure

The following configuration procedure provides the major AAA and RADIUS configuration on the
access device. The configuration procedures on the 802.1X client and RADIUS server are beyond
the scope of this configuration example. For information about AAA and RADIUS configuration
commands, see HPE FlexNetwork MSR Router Series Comware 5 Security Command Reference.
1.
Configure 802.1X client. Make sure the client is able to update its IP address after the access
port is assigned to the 802.1X guest VLAN or a server-assigned VLAN. (Details not shown.)
2.
Configure the RADIUS servers, user accounts, and authorization ACL, ACL 3000 in this
example. (Details not shown.)
3.
Configure the access device:
# Assign IP addresses to interfaces. (Details not shown.)
# Configure the RADIUS scheme.
<Device> system-view
[Device] radius scheme 2000
Figure
45, the host at 192.168.1.10 connects to port Ethernet 1/1 of the network access
106

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the FlexNetwork MSR Series and is the answer not in the manual?

Table of Contents