Got it

MAC + 802.1x authentication for wired user(802.1x first)

Latest reply: Dec 29, 2018 06:07:10 455 5 9 0

203831z0mz4uf4m4hkhwhk.png

203837kxroccozjgggg1o6.png

1. User message trigger Authentication

2. Switch launched 802.1X certification, terminal input user password for certification

3. When the server does not respond or the response fails, the switch initiates MAC authentication

configuration example


radius-server template controller_12.36
 radius-server shared-key cipher %^%#}gu$V!77QTf_=E.XK49#cLg'Smo}T!v8mIBwkKz0%^%#
 radius-server authentication 12.12.12.36 1812 weight 80
#
aaa
 authentication-scheme radius
  authentication-mode radius
 domain radius
  authentication-scheme radius
  radius-server controller_12.36
#

#
mac-access-profile name mac_access_profile
#
dot1x-access-profile name dot1x_access_profile
#
authentication-profile name mac_dot1x
 dot1x-access-profile dot1x_access_profile
 mac-access-profile mac_access_profile
 access-domain radius
 authentication dot1x-mac-bypass
#

#
interface GigabitEthernet1/0/1
 port link-type access
 port default vlan 200
 authentication-profile mac_dot1x
#


  • x
  • convention:

Mysterious.color
Created Dec 25, 2018 13:35:24 Helpful(0) Helpful(0)

very useful and clear
View more
  • x
  • convention:

Core%20Engineer%2C%20Technical%20Department.%20High%20experience%20in%20Networking
yjhd
Created Dec 28, 2018 02:07:06 Helpful(0) Helpful(0)

radius-server template controller_12.36
radius-server shared-key cipher %^%#}gu$V!77QTf_=E.XK49#cLg'Smo}T!v8mIBwkKz0%^%#
radius-server authentication 12.12.12.36 1812 weight 80
View more
  • x
  • convention:

SupperRobin
Created Dec 29, 2018 03:07:34 Helpful(0) Helpful(0)

To resolve wireless local area network (LAN) security issues, the Institute of Electrical and Electronics Engineers (IEEE) 802 LAN/wide area network (WAN) committee developed the 802.1X protocol. Later, the 802.1X protocol was widely applied as a common access control mechanism on LAN interfaces for authentication and security on Ethernet networks.
View more
  • x
  • convention:

Finn92
Created Dec 29, 2018 03:15:10 Helpful(0) Helpful(0)

It is recommended that the re-authentication interval be set to the default value. If multiple ACLs need to be delivered during user authorization, you are advised to disable the re-authentication function or set a longer re-authentication interval to improve the device's processing performance.

In remote authentication and authorization, if the re-authentication interval is set to a shorter time, the CPU usage may be higher.
View more
  • x
  • convention:

Torrent
Created Dec 29, 2018 06:07:10 Helpful(0) Helpful(0)

1. User message trigger Authentication

2. Switch launched 802.1X certification, terminal input user password for certification

3. When the server does not respond or the response fails, the switch initiates MAC authentication
thanks for sharing, we learned a lot
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."

My Followers

Login and enjoy all the member benefits

Login

Huawei Enterprise Support Community
Huawei Enterprise Support Community
Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.