Chapter12DOT1XConguration
DOT1XConfiguration
Example
Dot1xRadiusAuthentication
Application
WorkstationofauserisconnectedtoEthernetAoftheEthernet
switch.ThisisshowninFigure29.
FIGURE29DOT1XRADIUSAUTHENTICATIONAPPLICATION
Thefollowingneedstobeimplementedontheswitch:
�Conductuseraccessauthenticationoneachporttocontrolthe
user’saccesstotheInternet.
�ItisrequiredthattheaccesscontrolmodeisMACaddress-
basedaccesscontrolmode.
�AlltheAAAaccessusersbelongtothedefaultdomain
zte163.net.
�ThisauthenticationandRADIUSauthenticationareconducted
atthesametime.
�DisconnecttheuserandmakeitofineifRADIUSaccounting
fails.
�Donotaddthedomainnameaftertheusernameduringac-
cess.
�ConnecttheservergroupcomposedoftwoRADIUSservers
totheswitch.IPaddressesoftheseserversare10.1.1.1and
10.1.1.2respectively.Itisrequiredthattheformerservesas
themasterauthentication/slavechargingserverandthelatter
servesastheslaveauthentication/masterchargingserver .
CondentialandProprietaryInformationofZTECORPORATION137