Chapter7ServiceConguration
FIGURE75ACCESSAUTHENTICATIONCONFIGURATIONEXAMPLE
1.conguredot1xcommands
zte(cfg)#setport2securityenable
zte(cfg)#confignas
zte(cfg-nas)#aaaport2dot1xenable
zte(cfg-nas)#aaaport2keepaliveenable
zte(cfg-nas)#aaaport2accountingenable
2.congureradiuscommands
zte(zte)#confignas
zte(cfg-nas)#radiusispzteenable
zte(cfg-nas)#radiusispztedefaultispenable
zte(cfg-nas)#radiusispztesharedsecretisam
zte(cfg-nas)#radiusispzteclient192.168.20.20
zte(cfg-nas)#radiusispzteaddaccounting192.168.20.1991812
zte(cfg-nas)#radiusispzteaddauthentication192.168.20.1991813
3.EnableradiusclientsoftwareonPCandinputcorrectusername
andpassword.Thentheauthenticationrequestislaunched.
Whentheauthenticationrequestsucceeds,viewtheuserin-
formationbyusingthecommandshowclient.
zte(cfg)#showclient
MaxClients:256HistoryAccessClientsTotal:1
OnlineClients:1HistoryFailureClientsTotal:0
IndexUserNameAuthorizedPortIdVlanIdMacAddressElapsedTime
------------------------------------------------
------------
0zhouzhouyes2100.0a.eb.93.10.230:0:0:7
Caution:
DisablethesecurityproxysuchasSygatebeforetheuserPCsend-
ingauthenticationrequest.
CondentialandProprietaryInformationofZTECORPORATION181