Chapter 11 DOT1x Configuration
DOT1x Configuration
Examples
Dot1x Radius Authentication
Application
Workstation of a user is connected to Ethernet A of the Ethernet
switch. This is shown in
Figure 30
.
F
IGURE
30 D
OT
1
X
R
ADIUS
A
UTHENTICATION
A
PPLICATION
The following procedures are required to be implemented on the
switch:
�
Conduct user access authentication on each port to control the
user’s access to the Internet.
�
It is required that the access control mode is MAC address-
based access control mode.
�
All AAA access users belong to the default domain zte163.net.
�
This authentication and RADIUS authentication are conducted
at the same time.
�
Disconnect the user and make it offline if RADIUS accounting
fails.
�
Do not add the domain name after the user name during ac-
cess.
�
Connect the server group composed of two RADIUS servers
to the switch. IP addresses of these servers are 10.1.1.1 and
10.1.1.2 respectively. It is required that the former serves
as the master authentication/slave accounting server and the
latter serves as the slave authentication/master accounting
server.
�
Set the encryption key to be “aaazte” when the system ex-
changes packets with the authentication RADIUS server. Set
the system to resend packets to the RADIUS server if no re-
sponse comes from this server within five seconds after the
Confidential and Proprietary Information of ZTE CORPORATION
117