Figure 5-23 Access Authentication Configuration Instance - Zte ZXR10 5250 Series Configuration Manual

Gigabit-port intelligent switch
Hide thumbs Also See for ZXR10 5250 Series:
Table of Contents

Advertisement

console port and configure the access server, and then enable client software on the
user PC to originate authentication request. See

Figure 5-23 Access Authentication Configuration Instance

l
Configuration Procedure
1. Configure layer-3 interface commands
zte(cfg-router)#set ipport 0 ip 10.40.89.106/24
zte(cfg-router)#set ipport 0 vlan 1
zte(cfg-router)#set ipport 0 enable
2. Configure 802.1X commands
zte(cfg)#set port 2 security enable
zte(cfg)#config nas
zte(cfg-nas)#aaa-control port 2 dot1x enable
zte(cfg-nas)#aaa-control port 2 keepalive enable
zte(cfg-nas)#aaa-control port 2 accounting enable
3. Configure radius commands
zte(zte)#config nas
zte(cfg-nas)#radius isp zte enable
zte(cfg-nas)#radius isp zte defaultisp enable
zte(cfg-nas)#radius isp zte sharedsecret 1234
zte(cfg-nas)#radius isp zte client 10.40.89.106
zte(cfg-nas)#radius isp zte add accounting 10.40.89.78
zte(cfg-nas)#radius isp zte add authentication 10.40.89.78
4. Enable radius client software on the PC and input a correct username and
password. Then the authentication request is sent.
Note:
Disable the security proxy such as Sygate before the user PC sending the
authentication request.
l
Configuration Verification
SJ-20131111172707-002|2013-11-27 (R1.0)
Chapter 5 Service Configuration
Figure
5-77
ZTE Proprietary and Confidential
5-23.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents