ZXR102900ESeriesCongurationGuide
consoleportandconguretheaccessserver,andthenenableclientsoftwareonthe
userPCtooriginateauthenticationrequest.SeeFigure5-23.
Figure5-23AccessAuthenticationCongurationInstance
lCongurationProcedure
1.Congurelayer-3interfacecommands
zte(cfg-router)#setipport0ip10.40.89.106/24
zte(cfg-router)#setipport0vlan1
zte(cfg-router)#setipport0enable
2.Congure802.1Xcommands
zte(cfg)#setport2securityenable
zte(cfg)#confignas
zte(cfg-nas)#aaa-controlport2dot1xenable
zte(cfg-nas)#aaa-controlport2keepaliveenable
zte(cfg-nas)#aaa-controlport2accountingenable
3.Congureradiuscommands
zte(zte)#confignas
zte(cfg-nas)#radiusispzteenable
zte(cfg-nas)#radiusispztedefaultispenable
zte(cfg-nas)#radiusispztesharedsecret1234
zte(cfg-nas)#radiusispzteclient10.40.89.106
zte(cfg-nas)#radiusispzteaddaccounting10.40.89.78
zte(cfg-nas)#radiusispzteaddauthentication10.40.89.78
4.EnableradiusclientsoftwareonthePCandinputacorrectusernameand
password.Thentheauthenticationrequestissent.
Note:
DisablethesecurityproxysuchasSygatebeforetheuserPCsendingthe
authenticationrequest.
lCongurationVerication
5-78
SJ-20130731155059-002|2013-11-27(R1.0)ZTEProprietaryandCondential