本地没有radius服务器可以做802.1X认证吗,无线跟有线需要同时有802.1X认证是不是无线的做在AC上面,有线的做在交换机上面。
(0)
最佳答案
您好,做本地,参考
AC的配置:
1. 使能默认域imc
[AC] domain default enable imc
2. 使能端口安全
[AC] port-security enable
3. 将dot1x认证方式为EAP
[AC] dot1x authentication-method eap
4. 配置radius
[AC] radius scheme imc
[AC-radius-imc] server-type extended
[AC-radius-imc] primary authentication 192.168.1.10
[AC-radius-imc] primary accounting 192.168.1.10
[AC-radius-imc] key authentication h3c
[AC-radius-imc] key accounting h3c
[AC-radius-imc] user-name-format without-domain
5. 配置domain域imc
[AC] domain imc
[AC-isp-imc] authentication lan-access radius-scheme imc
[AC-isp-imc] authorization lan-access radius-scheme imc
[AC-isp-imc] accounting lan-access radius-scheme imc
6. 配置服务模版,选择安全协议为wpa,加密方式为tkip
[AC] wlan service-template 1 crypto
[AC-wlan-st-1] ssid h3c-wpa
[AC-wlan-st-1] bind WLAN-ESS 1
[AC-wlan-st-1] cipher-suite tkip
[AC-wlan-st-1] security-ie wpa
[AC-wlan-st-1] service-template enable
7. 配置端口安全模式
[AC] interface WLAN-ESS1
[AC-WLAN-ESS1] port access vlan 10
[AC-WLAN-ESS1] port-security port-mode userlogin-secure-ext
[AC-WLAN-ESS1] port-security tx-key-type 11key
[AC-WLAN-ESS1] undo dot1x handshake
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论