Thanks, we are getting closer but the host still cannot access the internet after authentication. Please see stripped down config of our switch. We have a Pre-Auth-ACL on the port limiting access to one subnet. Once authenticated we want the ACL specified in RADIUS using Filter-Id (ACL 3001) to overwrite the Pre-Auth-ACL. I have included a display result at the end:
radius-server template dot1xauth
radius-server shared-key cipher *********
radius-server authentication 10.2.3.3 1812 weight 80
radius-server accounting 10.2.3.3 1813 weight 80
acl number 3001
rule 10 permit ip
acl name Pre-Auth-ACL 3999
rule 10 permit ip destination 10.3.0.0 0.0.255.255
rule 20 deny ip
aaa
authentication-scheme radius
authentication-mode radius local
accounting-scheme default
accounting-scheme dot1xacc
accounting-mode radius
domain dot1xauth
authentication-scheme radius
accounting-scheme dot1xacc
radius-server dot1xauth
interface GigabitEthernet0/0/2
description AMTTEST2
port link-type access
port default vlan 5
traffic-filter inbound acl name Pre-Auth-ACL
dot1x domain dot1xauth
dot1x enable
dot1x max-user 1
dot1x port-method port
dot1x reauthenticate
dot1x authentication-method eap
[HUAWEI-GigabitEthernet0/0/2]dis access-user user 106
Basic:
User ID : 106
User name : host/AMTTEST2.test.com
Domain-name : dot1xauth
User MAC : 7054-d2c4-3fcb
User IP address : 10.3.5.42
User vpn-instance : -
User IPv6 address : -
User access Interface : GigabitEthernet0/0/2
User vlan event : Success
QinQVlan/UserVlan : 0/5
User vlan source : server vlan
User access time : 2019/04/05 10:06:10 DST
User accounting session ID : HUAWEI00002000000005527625000006a
Option82 information : -
User access type : 802.1x
Terminal Device Type : Data Terminal
Dynamic VLAN ID : 5
Dynamic ACL number(Effective) : 3001
Session Timeout : 3600(s), Remaining: 3596(s)
Termination Action : RE-AUTHENTICATION
AAA:
User authentication type : 802.1x authentication
Current authentication method : RADIUS
Current authorization method : -
Current accounting method : RADIUS