SNR S2989G-8TX — настройка функций безопасности для сетевых устройств [317/553]

Превью страниц Страница 317 / 553
SNR S2989G-48TX [317/553] X troubleshooting
S2989G-24TX Operation Manual
Chapter 6 Security Function Configuration
6-44
Switch(Config-if-vlan1)#exit
Switch(config)#radius-server authentication host 2004:1:2:3::3
Switch(config)#radius-server accounting host 2004:1:2:3::3
Switch(config)#radius-server key test
Switch(config)#aaa enable
Switch(config)#aaa-accounting enable
Switch(config)#dot1x enable
Switch(config)#interface ethernet 1/0/2
Switch(Config-If-Ethernet1/0/2)#dot1x enable
Switch(Config-If-Ethernet1/0/2)#dot1x port-control auto
Switch(Config-If-Ethernet1/0/2)#exit
6.2.4
802.1x Troubleshooting
It is possible that 802.1x be configured on ports and 802.1x authentication be set to
auto, t switch can’t be to authenticated state after the user runs 802.1x supplicant
software. Here are some possible causes and solutions:
If 802.1x cannot be enabled for a port, make sure the port is not executing MAC
binding, or configured as a port aggregation. To enable the 802.1x authentication, the
above functions must be disabled.
If the switch is configured properly but still cannot pass through authentication,
connectivity between the switch and RADIUS server, the switch and 802.1x client
should be verified, and the port and VLAN configuration for the switch should be
checked, too.
Check the event log in the RADIUS server for possible causes. In the event log, not
only unsuccessful logins are recorded, but prompts for the causes of unsuccessful
login. If the event log indicates wrong authenticator password, radius-server key
parameter shall be modified; if the event log indicates no such authenticator, the
authenticator needs to be added to the RADIUS server; if the event log indicates no
such login user, the user login ID and password may be wrong and should be verified
and input again.

Содержание

666

Узнайте, как правильно настроить функции безопасности на сетевых устройствах, включая аутентификацию и устранение неполадок 802.1x. Полезные советы и рекомендации.