Juniper JUNOS OS 10.3 - SOFTWARE Manual page 2662

For ex series ethernet switches
Hide thumbs Also See for JUNOS OS 10.3 - SOFTWARE:
Table of Contents

Advertisement

Complete Software Guide for Junos
Table 336: Components of the MAC RADIUS Authentication Configuration Topology (continued)
Property
Connections to printers (no PoE required)
RADIUS server
Configuration
CLI Quick
Configuration
Step-by-Step
Procedure
2566
®
OS for EX Series Ethernet Switches, Release 10.3
Settings
ge-0/0/19
ge-0/0/20
Connected to the switch on interface
The printer with the MAC address 00040ffdacfe is connected to access interface
ge-0/0/19
. A second printer with the MAC address 0004aecd235f is connected to access
interface
. In this example, both interfaces are configured for MAC RADIUS
ge-0/0/20
authentication on the switch, and the MAC addresses (without colons) of both printers
are configured on the RADIUS server. Interface
normal delay while the switch attempts 802.1X authentication; MAC RADIUS
authentication is enabled and 802.1X authentication is disabled using the
option.
restrict
To configure MAC RADIUS authentication on the switch, perform these tasks:
To quickly configure MAC RADIUS authentication, copy the following commands and
paste them into the switch terminal window:
[edit]
set protocols dot1x authenticator interface ge-0/0/19 mac-radius
set protocols dot1x authenticator interface ge-0/0/20 mac-radius restrict
NOTE: You must also configure the two MAC addresses as usernames and
passwords on the RADIUS server, as is done in step 2 of the Step-by-Step
Procedure.
Configure MAC RADIUS authentication on the switch and on the RADIUS server:
On the switch, configure the interfaces to which the printers are attached for MAC
1.
RADIUS authentication, and configure the
so that only MAC RADIUS authentication is used:
[edit]
user@switch# set protocols dot1x authenticator interface ge-0/0/19 mac-radius
user@switch# set protocols dot1x authenticator interface ge-0/0/20 mac-radius
restrict
On the RADIUS server, configure the MAC addresses
2.
as usernames and passwords:
0004aecd235f
[root@freeradius]#
edit /etc/raddb
vi users
00040ffdacfe Auth-type:=EAP, User-Password = "00040ffdacfe"
0004aecd235f Auth-type:=EAP, User-Password = "0004aecd235f"
, MAC address 00040ffdacfe
, MAC address 0004aecd235f
ge-0/0/10
ge-0/0/20
option on interface
restrict
Copyright © 2010, Juniper Networks, Inc.
is configured to eliminate the
mac-radius
ge-0/0/20
and
00040ffdacfe
,

Advertisement

Table of Contents
loading

Table of Contents