Qtech QSW-2900-24T-AC [165/209] Chapter 11

11-163
Chapter 11 802.1X Configuration Command
11.1 Brief introduction of 802.1X configuration
IEEE 802.1X is the accessing management protocol standard based on interface accessing control passed in
June, 2001. Traditional LAN does not provide accessing authentication. User can acess the devices and resources in
LAN when connecting to the LAN, which is a security hidden trouble. For application of motional office and CPN,
device provider hopes to control and configure users connecting. There is also the need for accounting.
IEEE 802.1X is a network accessing control technology based on interface which is the accessing devices
authentication and control by physical accessing level of LAN devices. Physical accessing level here means the
interface of LAN Switch devices. When authentication, switch is the in-between (agency) of client and
authentication server. It obtains users identity from client of accessing switch and verifies the information through
authentication server. If the authentication passes, this user is allowed to access LAN resources or it will be refused.
System realizes IEEE 802.1X authentication. Use IEEE 802.1X authentication needs: RADIUS server which
system can access to make the authentication informayion to send to; IEEE 802.1X authentication client software
installed in accessing users device (such as PC).
11.2 802.1X Configuration
Configure system or interface related parameter before enabling 802.1X authentication and these
configurations will be saved after disabling 802.1X. And the parameter will be effective after re-enabling 802.1X.
802.1X configuration list is as following:
· Configure RADIUS project
· Configure domain
· Configure 802.1X
11.2.1 AAA configuration mode
Finish necessary configuration of domain and RADIUS project of 802.1X authentication.
Use aaa command in global configuration mode to enter AAA configuration mode.
For example:
! Enter AAA configuration mode
QTECH(config)#aaa
QTECH(config-aaa)#
11.2.2 RADIUS Server Configuration
RADIUS server saves valid users identity. When authentication, system transfers users identity to RADIUS
server and transfer the validation to user.
User accessing to system can access LAN resources after authentication of RADIUS server.
The main configuration command of domain is as following:
· radius host
· primary-ip

Содержание

Скачать
Случайные обсуждения