53 
[SwitchA] dot1x 
[SwitchA] interface gigabitethernet 1/0/1 
[SwitchA-GigabitEthernet1/0/1] dot1x 
[SwitchA-GigabitEthernet1/0/1] quit 
[SwitchA] interface gigabitethernet 1/0/2 
[SwitchA-GigabitEthernet1/0/2] dot1x 
[SwitchA-GigabitEthernet1/0/2] quit 
3.  Configure Switch B: 
# Globally enable IGMP snooping.  
<SwitchB> system-view 
[SwitchB] igmp-snooping 
[SwitchB-igmp-snooping] quit 
# Create VLAN 104, assign GigabitEthernet 1/0/1 through GigabitEthernet 1/0/3 to this VLAN, 
and enable IGMP snooping in this VLAN.  
[SwitchB] vlan 104 
[SwitchB-vlan104] port gigabitethernet 1/0/1 to gigabitethernet 1/0/3 
[SwitchB-vlan104] igmp-snooping enable 
[SwitchB-vlan104] quit 
# Create a user profile profile2 to allow users to join or leave only one multicast group, 224.1.1.1. 
Then, enable the user profile.  
[SwitchB] acl number 2001 
[SwitchB-acl-basic-2001] rule permit source 224.1.1.1 0 
[SwitchB-acl-basic-2001] quit 
[SwitchB] user-profile profile2 
[SwitchB-user-profile-profile2] igmp-snooping access-policy 2001 
[SwitchB-user-profile-profile2] quit 
[SwitchB] user-profile profile2 enable 
# Create a RADIUS scheme scheme2; set the service type for the RADIUS server to extended; 
specify the IP addresses of the primary authentication/authorization server and accounting server 
as 3.1.1.1; set the shared keys to 321123; specify that a username sent to the RADIUS server 
carry no domain name. 
[SwitchB] radius scheme scheme2 
[SwitchB-radius-scheme2] server-type extended 
[SwitchB-radius-scheme2] primary authentication 3.1.1.1 
[SwitchB-radius-scheme2] key authentication 321123 
[SwitchB-radius-scheme2] primary accounting 3.1.1.1 
[SwitchB-radius-scheme2] key accounting 321123 
[SwitchB-radius-scheme2] user-name-format without-domain 
[SwitchB-radius-scheme2] quit 
# Create an ISP domain domain2; reference scheme2 for the authentication, authorization, and 
accounting of LAN users; specify domain2 as the default ISP domain. 
[SwitchB] domain domain2 
[SwitchB-isp-domian2] authentication lan-access radius-scheme scheme2 
[SwitchB-isp-domian2] authorization lan-access radius-scheme scheme2 
[SwitchB-isp-domian2] accounting lan-access radius-scheme scheme2