Operation Manual – AAA-RADIUS-HWTACACS-EAD
H3C S3600 Series Ethernet Switches-Release 1510 Chapter 2
EAD Configuration
2-4
II. Network diagram
Ethernet 1/0/1
Security policy server
IP Address:10.110.91.166
Virus patch server
(IP Address:10.110.91.168 )
Authentication server
(IP Address 10.110.91.164 )
Internet
Internet
User
Ethernet 1/0/1
Security policy server
IP address:10.110.91.166
Virus patch server
IP address:10.110.91.168
Authentication server
IP address 10.110.91.164
Internet
Internet
User
Internet
Internet
Internet
Internet
Ethernet 1/0/1
Security policy server
IP Address:10.110.91.166
Virus patch server
(IP Address:10.110.91.168 )
Authentication server
(IP Address 10.110.91.164 )
Internet
Internet
User
Ethernet 1/0/1
Security policy server
IP Address:10.110.91.166
Virus patch server
(IP Address:10.110.91.168 )
Authentication server
(IP Address 10.110.91.164 )
Internet
Internet
Virus patch server
(IP Address:10.110.91.168 )
Authentication server
(IP Address 10.110.91.164 )
Internet
Internet
User
Ethernet 1/0/1
Security policy server
IP address:10.110.91.166
Virus patch server
IP address:10.110.91.168
Authentication server
IP address 10.110.91.164
Internet
Internet
Virus patch server
IP address:10.110.91.168
Authentication server
IP address 10.110.91.164
Internet
Internet
User
Internet
Internet
Internet
Internet
Figure 2-2 EAD configuration
III. Configuration procedure
# Configure 802.1x on the switch. Refer to the 802.1x part in H3C S3600 Series
Ethernet Switches Operation Manual for detailed description.
# Configure a domain.
<H3C> system-view
[H3C] domain system
[H3C-isp-system] quit
# Configure a RADIUS scheme.
[H3C] radius scheme cams
[H3C-radius-cams] primary authentication 10.110.91.164 1812
[H3C-radius-cams] accounting optional
[H3C-radius-cams] key authentication expert
[H3C-radius-cams] server-type extended
# Configure the IP address of the security policy server.
[H3C-radius-cams] security-policy-server 10.110.91.166
# Associate the domain with the RADIUS scheme.
[H3C-radius-cams] quit
[H3C] domain system
[H3C-isp-system] radius-scheme cams