H3C S7500 Series Operation Manual page 517

Hide thumbs Also See for S7500 Series:
Table of Contents

Advertisement

Operation Manual – 802.1x
H3C S7500 Series Ethernet Switches
II. Network diagram
Supplicant
Figure 1-11 Network diagram for AAA configuration with 802.1x and RADIUS enabled
III. Configuration procedure
Note:
Following configuration covers the major AAA/RADIUS configuration commands. You
can refer to AAA-RADIUS-HWTACACS-EAD Operation Manual for information about
these commands. Configurations on the client and the RADIUS servers are omitted.
# Enable 802.1x globally.
<H3C> system-view
System View: return to User View with Ctrl+Z.
[H3C] dot1x
# Enable 802.1x for Ethernet 2/0/1.
[H3C] dot1x interface Ethernet 2/0/1
# Set the access control method to MAC-address-based (This command can be
omitted as MAC-address-based is the default configuration).
[H3C] dot1x port-method macbased interface Ethernet 2/0/1
# Create a RADIUS scheme named radius1 and enter RADIUS scheme view.
[H3C] radius scheme radius1
# Assign IP addresses to the primary authentication and accounting RADIUS servers.
[H3C-radius-radius1] primary authentication 10.11.1.1
[H3C-radius-radius1] primary accounting 10.11.1.2
# Assign IP addresses to the secondary authentication and accounting RADIUS
servers.
[H3C-radius-radius1] secondary authentication 10.11.1.2
Authenticati
(RADIUS s
10 .1.1.1
10 .1.1.2
Eth2 /0/1
Authenticator
1.1 .1.1/24
Switch
1-20
Chapter 1 802.1x Configuration
on servers
erver cluster)
Internet

Advertisement

Table of Contents
loading

Table of Contents