80
C
3: C
HAPTER
ONFIGURING A
WX1200# set radius server svr1 address 10.10.70.20 key rad1pword
success: change accepted.
WX1200# set radius server svr2 address 10.10.70.40 key rad2pword
success: change accepted.
WX1200# set server group grp1 members svr1 svr2
success: change accepted.
WX1200# set server group grp1 load-balance enable
success: change accepted.
WX1200# display aaa
Default Values
authport=1812 acctport=1813 timeout=5 acct-timeout=5
retrans=3 deadtime=0 key=(null) author-pass=(null)
Radius Servers
Server
-------------------------------------------------------------------
svr1
svr2
Server groups
grp1 (load-balanced): svr1 svr2
WX S
B
WITCH FOR
ASIC
display aaa
The following commands configure two RADIUS servers, add them to
server group grp1, enable load balancing of authentication sessions
among the servers, and verify the change:
Addr
10.10.70.20
10.10.70.40
Configuring the Authentication Protocol for Pass-Through
Authentication
To configure the authentication protocol for 802.1X users, use the
following command:
set authentication dot1x {ssid ssid-name | wired} user-glob
[bonded] protocol method1 [method2] [method3] [method4]
To verify the change, use the following command:
display aaa
The asterisk in the example below is a wildcard. You cannot use a
wildcard to represent the delimiter characters in user globs, which are the
at sign (@) and the dot (
you must specify the delimiter in the user glob as shown in these
S
ERVICE
Ports
T/o Tries Dead State
1812 1813
5
1812 1813
5
). To match a username that contains a delimiter,
.
3
0
UP
3
0
UP
Need help?
Do you have a question about the 3CRWX120695A and is the answer not in the manual?