cisco 交换机结合IMC EAD做802.1X+Cert+病毒库检,cisco 交换机应该如何配置,switch接口应该如何配置?接口如果用authentication open,認不認證網絡都能通,ACL應該如何寫?接口應該用什麽authentication mode?
aaa new-model
aaa group server radius H3Cradius
server 192.168.100.1 auth-port 1812 acct-port 1813
aaa authentication dot1x default group H3Cradius
aaa authorization network default local group radius group H3Cradius
aaa accounting update periodic 1
aaa accounting exec TEK start-stop group radius
aaa accounting network default start-stop group radius group H3Cradius
aaa accounting connection TEK start-stop group radius
aaa session-id common
authentication mac-move permit
dot1x system-auth-control
identity profile dot1x
interface GigabitEthernet1/0/1
switchport access vlan 4
switchport mode access
ip access-group denyinACL in
authentication open
authentication port-control auto
authentication periodic
authentication timer reauthenticate 36000
dot1x pae authenticator
dot1x timeout quiet-period 300
dot1x timeout server-timeout 3600
spanning-tree portfast
interface Vlan4
ip address 172.22.40.238 255.255.255.0
!
ip default-gateway 172.22.40.254
radius-server attribute 6 on-for-login-auth
radius-server attribute 8 include-in-access-req
radius-server attribute 25 access-request include
radius-server attribute 11 default direction in
radius-server attribute nas-port format c
radius-server host 192.168.100.1 auth-port 1812 acct-port 1813 key admin
radius-server retransmit 1
radius-server timeout 3
snmp-server community admin RW
snmp-server host 192.168.100.1 version 2c admin
snmp ifmib ifindex persist
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论