ZXR105900/5200SeriesUserManual(BasicCongurationVolume)
�Settheencryptionpasswordto“aaazte”whenthesystemex-
changespacketswiththeauthenticationRADIUSserver .Set
thesystemtoresendpacketstotheRADIUSserverifnore-
sponsecomesfromthisserverwithinvesecondsafterthe
previoussending,andpacketscanberesentforvetimesat
most.Directthesystemtoremovetheuserdomainnamefrom
theusernameandthensendittotheRADIUSserver .
Switchconguration:
ZXR10(config)#radiusauthentication-group1
ZXR10(config-authgrp-1)#server110.1.1.1keyaaazteport
<authserverportnum>
ZXR10(config-authgrp-1)#server210.1.1.2keyaaazteport
<authserverportnum>
ZXR10(config-authgrp-1)#exit
ZXR10(config)#radiusaccounting-group1
ZXR10(config-acctgrp-1)#server110.1.1.1keyaaazteport
<acctserverportnum>
ZXR10(config-acctgrp-1)#server210.1.1.2keyaaazteport
<acctserverportnum>
ZXR10(config-acctgrp-1)#exit
ZXR10(config)#nas
ZXR10(config-nas)#dot1xre-authenticationenableperiod5
ZXR10(config-nas)#dot1xmax-request5
ZXR10(config-nas)#createaaa1portgei_1/1
ZXR10(config-nas)#aaa1authenticationradius
ZXR10(config-nas)#aaa1controldot1xenable
ZXR10(config-nas)#aaa1authorizationauto
ZXR10(config-nas)#aaa1accountingenable
ZXR10(config-nas)#aaa1multiple-hostsenable
ZXR10(config-nas)#aaa1default-ispzte163.net
ZXR10(config-nas)#aaa1fullaccountdisable
ZXR10(config-nas)#aaa1radius-serverauthentication1
ZXR10(config-nas)#aaa1radius-serveraccounting1
ZXR10(config-nas)#aaa1authenradius
Dot1xTrunkAuthentication
Application
InternalnetworkofanenterpriseisshowninFigure30.
FIGURE30DOT1XTRUNKAUTHENTICATIONAPPLICATION
138CondentialandProprietaryInformationofZTECORPORATION