34-2
thentication environment.
figuration of security policy server IP address. For other related
configuration, refer to
AAA Overview
z
Configuring a RADIUS scheme.
z
Configuring the IP address of the security policy server.
z
Associating the ISP domain with the RADIUS scheme.
EAD is commonly used in RADIUS au
This section mainly describes the con
.
Follow these step
nfigure EAD:
s to co
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter RADIUS scheme
view
radius scheme
radius-scheme-name
—
Configure the RADIUS
server type to
extended
server-type extended
Required
Configure the IP address of
a security policy server
security-policy-server
ip-address
pports
up to eight IP addresses of
security policy servers.
Required
Each RADIUS scheme su
EAD Configuration Example
Network requirements
In
Figure 34-2
:
z
A user is connected to Ethernet 1/0/1 on the switch.
The user adopts 802.1x client supporting EAD extend
z
ed function.
h to use RADIUS server for remote user authentication and
The
64 and the switch, and configure the switch
z
entication server type to
extended
.
n the switch and RADIUS
server to
expert
.
z
Configure the IP address 10.110.91.166 of the security policy server.
z
You are required to configure the switc
use security policy server for EAD control on users.
following are the configuration tasks:
z
Connect the RADIUS authentication server 10.110.91.1
to use port number 1812 to communicate with the server.
Configure the auth
z
Configure the encryption password for exchanging messages betwee