Operation Manual – 802.1x
Quidway S3100 Series Ethernet Switches Chapter 1
802.1x Configuration
Huawei Technologies Proprietary
1-21
secondary counting server, and the latter the secondary authentication and the
primary counting server. Configure the interaction password between the switch
and the authenticating RADIUS server to be “name”, and “money” for interaction
between the switch and the counting RADIUS. Configure the waiting period for the
switch to resend packets to the RADIUS server to be 5 seconds, that is, if after 5
seconds the RADIUS still has not sent any responses back, the switch will resend
packets. Configure the number of times that a switch resends packets to the
RADIUS server to be 5. Configure the switch to send real-time counting packets to
the RADIUS server every 15 minutes with the domain names removed from the
user name beforehand.
z The user name and password for local 802.1x authentication are “localuser” and
“localpass” (in plain text) respectively. The idle disconnecting function is enabled.
II. Network diagram
Su
licant
Authentication serv
(RADIUS server clu
IP address: 10.11.1.1
10.11.1.2
ers
ster
)
Internet
Authenticator
Switch
Supplicant
Authentication se
(RADIUS server c
IP address: 10.11.
10.1
rver
luster
1.1
1.1.2)
Internet
Authenticator
Switch
Ethernet1/0/1
Su
licant
Authentication serv
(RADIUS server clu
IP address: 10.11.1.1
10.11.1.2
ers
ster
)
Internet
Authenticator
Switch
Supplicant
Authentication se
(RADIUS server c
IP address: 10.11.
10.1
rver
luster
1.1
1.1.2)
Internet
Authenticator
Switch
Ethernet1/0/1
Figure 1-11 Network diagram for AAA configuration with 802.1x and RADIUS enabled
III. Configuration procedure
Note:
Following configuration covers the major AAA/RADIUS configuration commands. You
can refer to AAA&RADIUS Operation Manual for the information about these
commands. Configuration on the client and the RADIUS servers is omitted.
What follows next covers the majority of AAA/RADIUS configuration commands. For
further information, refer to the AAA & RADIUS Operation Manual. Configuration on the
client and the RADIUS server is omitted here.
# Enable 802.1x globally.
<Quidway>system-view