Aaa For 802.1X Users By A Radius Server - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Total 1 user(s) matched, 1 listed.
# Use the display connection command to view the connection information on the switch.
[Switch] display connection
Index=20
IP=192.168.1.58
IPv6=N/A
MAC=00-15-E9-A6-7C-FE
Total 1 connection(s) matched.

AAA for 802.1X users by a RADIUS server

Network requirements
As shown in
Use the RADIUS server for authentication, authorization, and accounting of 802.1X users.
Use MAC-based access control on GigabitEthernet 1/0/1 to authenticate all 802.1X users on the
port separately.
Include the domain name in a username sent to the RADIUS server.
On the RADIUS server, add a service that charges 120 dollars for up to 120 hours per month and assigns
authenticated users to VLAN 4, configure a user with the name dot1x@bbb, and register the service for
the user.
Set the shared keys for secure RADIUS communication to expert. Set the ports for
authentication/authorization and accounting to 1812 and 1813, respectively.
Figure 25 Network diagram
 
Configuration procedure
1.
Configure the interfaces and VLANs as shown in
IP address manually or automatically and can access resources in the authorized VLAN after
passing authentication. (Details not shown.)
2.
Configure the RADIUS server (when the server runs on IMC PLAT 5.0):
NOTE:
This section assumes that the RADIUS server runs on IMC PLAT 5.0 (E0101) and IMC UAM 5.0 (E0101).
# Add the switch to the IMC Platform as an access device.
,Username=portal@dm1
Figure
25, configure the switch to:
Figure
25. Make sure that the host can get a new
60

Advertisement

Table of Contents
loading

Table of Contents