Chapter11DOT1xConguration
DOT1xConfiguration
Examples
Dot1xRadiusAuthentication
Application
WorkstationofauserisconnectedtoEthernetAoftheEthernet
switch.ThisisshowninFigure30.
FIGURE30DOT1XRADIUSAUTHENTICATIONAPPLICATION
Thefollowingproceduresarerequiredtobeimplementedonthe
switch:
�Conductuseraccessauthenticationoneachporttocontrolthe
user’saccesstotheInternet.
�ItisrequiredthattheaccesscontrolmodeisMACaddress-
basedaccesscontrolmode.
�AllAAAaccessusersbelongtothedefaultdomainzte163.net.
�ThisauthenticationandRADIUSauthenticationareconducted
atthesametime.
�DisconnecttheuserandmakeitofineifRADIUSaccounting
fails.
�Donotaddthedomainnameaftertheusernameduringac-
cess.
�ConnecttheservergroupcomposedoftwoRADIUSservers
totheswitch.IPaddressesoftheseserversare10.1.1.1and
10.1.1.2respectively.Itisrequiredthattheformerserves
asthemasterauthentication/slaveaccountingserverandthe
latterservesastheslaveauthentication/masteraccounting
server .
�Settheencryptionkeytobe“aaazte”whenthesystemex-
changespacketswiththeauthenticationRADIUSserver .Set
thesystemtoresendpacketstotheRADIUSserverifnore-
sponsecomesfromthisserverwithinvesecondsafterthe
CondentialandProprietaryInformationofZTECORPORATION117