Huawei Quidway S6500 Series Operation Manual page 451

Hide thumbs Also See for Quidway S6500 Series:
Table of Contents

Advertisement

Operation Manual - Security
Quidway S6500 Series Ethernet Switches
accessed, the domain name does not follow the user name. Normally, if the user's
traffic is less than 2kbps consistently over 20 minutes, he will be disconnected.
A server group, consisting of two RADIUS servers at 10.11.1.1 and 10.11.1.2
respectively, is connected to the switch. The former one acts as the
primary-authentication/second-accounting server. The latter one acts as the
secondary-authentication/primary-accounting server. Set the encryption key as "name"
when the system exchanges packets with the authentication RADIUS server and
"money" when the system exchanges packets with the accounting RADIUS server.
Configure the system to retransmit packets to the RADIUS server if no response
received in 5 seconds. Retransmit the packet no more than 5 times in all. Configure the
system to transmit a real-time accounting packet to the RADIUS server every 15
minutes. The system is instructed to transmit the user name to the RADIUS server after
removing the user domain name.
The user name of the local 802.1x access user is localuser and the password is
localpass (input in plain text). The idle cut function is enabled.
II. Networking diagram
Supplicant
Supplicant
Supplicant
Supplicant
Supplicant
Figure 1-2 Enabling 802.1x and RADIUS to perform AAA on the supplicant
III. Configuration procedure
Note:
The following examples concern most of the AAA/RADIUS configuration commands.
For details, refer to the chapter AAA and RADIUS Protocol Configuration.
The configurations of accessing user workstation and the RADIUS server are omitted.
Switch
Switch
Switch
Switch
Switch
Ethernet3/0/1
Authenticator
Authenticator
Authenticator
Authenticator
Authenticator
Huawei Technologies Proprietary
1-14
Chapter 1 802.1x Configuration
Authentication Serve
Authentication Serve
Authentication Serve
Authentication Serve
Authentication Serve
rs
rs
rs
rs
rs
(RADIUS Server Clu
(RADIUS Server Clu
(RADIUS Server Clu
(RADIUS Server Clu
(RADIUS Server Clu
ster
ster
ster
ster
ster
IP Address: 10.11.1.1
IP Address: 10.11.1.1
IP Address: 10.11.1.1
IP Address: 10.11.1.1
IP Address: 10.11.1.1
10.11.1
10.11.1
10.11.1
10.11.1
10.11.1
.2)
.2)
.2)
.2)
.2)
Internet
Internet
Internet
Internet
Internet

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Release 3000 series

Table of Contents