Configuring Dot1X; Configuring Aaa - Zte ZXR10 8900 Series User Manual

10 gigabit routing switch
Hide thumbs Also See for ZXR10 8900 Series:
Table of Contents

Advertisement

ZXR10 8900 Series User Manual (Basic Configuration Volume)
Authentication
Server System
Step Command
1
ZXR10(config)#
2
ZXR10(config-nas)#
<port-name>][vlan <vlan-id>]
3
ZXR10(config-nas)#
{dot1x|dot1x-relay}{enable|disable}
4
ZXR10(config-nas)#
{auto|locl|radius}
5
ZXR10(config-nas)#
{pap|chap|eap}
6
ZXR10(config-nas)#
[period <period-value>]|disable}
7
ZXR10(config-nas)#
{enable|disable}
8
ZXR10(config-nas)#
{enable [max-hosts <host-number>]|disable}
9
ZXR10(config-nas)#
<isp-name>
10
ZXR10(config-nas)#
{enable|disable}
11
ZXR10(config-nas)#
<group-name>
114
Confidential and Proprietary Information of ZTE CORPORATION
thentication channel for each user and other users cannot use the
logical channel after the port is enabled.
Authentication server is usually a
server user-related information is stored such as the VLAN where
the user locates, CAR parameter, priority and access control list
of the user. Once the user passes authentication, the authentica-
tion server delivers user-related information to the authentication
system which creates a dynamic access control list. The above
parameters are used to measure subsequent traffic of the user.
Authentication server and RADIUS server communicate with each
other through the RADIUS protocol.

Configuring DOT1x

Configuring AAA

To configure AAA, perform the following steps.
nas
create aaa <rule-id>[port
aaa <rule-id> control
aaa <rule-id> authentication
aaa <rule-id> protocol
aaa <rule-id> keepalive {enable
aaa <rule-id> accounting
aaa <rule-id> multiple-hosts
aaa <rule-id> default-isp
aaa <rule-id> fullaccount
aaa <rule-id> groupname
RADIUS
server. In authentication
Function
This enters nas configuration
mode
This creates AAA control entry
This enables/disables dot1x
authentication or relay
This selects an authentication
mode
This selects an authentication
protocol
This configures keepalive
interval
This configures to charge or
not
This configures whether
multiple users are allowed or
not and configures user quota
This configures the default
ISP server name
This configures whether to
contain ISP domain name in
user name
This configures a group name

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents