想咨询下我们的交换机端口启用了MAC地址认证,但是我又没在接入设备和认证服务器上找到MAC地址认证需要的账号和密码信息是什么呢?设备是通过安装802.1x认证客户端是可以接入网络的,但是现在就是不清楚MAC认证是怎么做到的?交换机配置如下:
version 5.20.99, Release 1109
#
sysname jieru7
#
clock timezone GMT add 08:00:00
#
domain default enable leagsoft
#
ipv6
#
telnet server enable
#
port-group-vlan 1
#
dot1x
dot1x authentication-method eap
#
mac-authentication
mac-authentication user-name-format mac-address with-hyphen
#
password-recovery enable
#
acl number 2110
rule 0 permit source 10.253.0.164 0
rule 5 permit source 10.253.0.1 0
rule 10 permit source 10.192.1.165 0
rule 15 permit source 10.254.7.162 0
rule 20 permit source 10.254.6.87 0
rule 25 permit source 127.0.0.1 0
rule 30 permit source 10.10.10.166 0
rule 55 permit source 10.10.10.222 0
#
acl number 3000
rule 10 permit ip destination 10.192.1.171 0
rule 15 permit ip destination 10.192.1.173 0
rule 20 permit tcp destination 10.192.1.171 0
rule 25 permit tcp destination 10.192.1.173 0
rule 50 deny ip
rule 55 deny tcp
#
vlan 1
#
vlan 8
#
vlan 10
#
vlan 20
#
vlan 30
#
vlan 50
#
vlan 100
#
vlan 3000
#
vlan 3074
#
radius scheme leagsoft
primary authentication 10.192.1.171 key cipher $c$3$n1PI03/KxaJiTTW8EMOHcZSvRgYCvYW07WtS
primary accounting 10.192.1.171 key cipher $c$3$0ibCSz/auf12XAhAu0Db57CwuaJZ4iivNP2T
secondary authentication 10.192.1.172 key cipher $c$3$VHV5GgAm7IrXOprLBT8q409iv/h3HD6+ADXf
secondary accounting 10.192.1.172 key cipher $c$3$/0k151SXgLliFdETuQAdhcxs5PILziQpv3Lt
user-name-format without-domain
#
domain leagsoft
authentication lan-access radius-scheme leagsoft none
authorization lan-access radius-scheme leagsoft none
accounting lan-access radius-scheme leagsoft none
access-limit disable
state active
idle-cut disable
self-service-url disable
domain system
access-limit disable
state active
idle-cut disable
self-service-url disable
#
user-group system
group-attribute allow-guest
#
local-user admin
password cipher $c$3$Yps2LbdCw3st4R0K2bUsBYAnnz6A/yxFE0sBZlY1dtbVG/A=
authorization-attribute level 3
service-type telnet terminal
service-type web
#
stp enable
#
interface Bridge-Aggregation1
port link-type trunk
port trunk permit vlan all
#
interface NULL0
#
interface Vlan-interface100
ip address 192.168.100.10 255.255.255.0
#
interface Vlan-interface3074
ip address 10.192.1.26 255.255.255.0
#
interface GigabitEthernet1/0/1
port access vlan 3000
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/2
port access vlan 3000
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/3
port access vlan 3000
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/4
port access vlan 3000
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/5
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/6
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/7
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/8
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/9
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/10
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/11
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/12
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/13
port access vlan 10
stp edged-port enable
mac-authentication timer auth-delay 30
#
interface GigabitEthernet1/0/14
description 王尊斌
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/15
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/16
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/17
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/18
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/19
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/20
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/21
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/22
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/23
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/24
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/25
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/26
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/27
description 朱远祺
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/28
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/29
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/30
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/31
port access vlan 10
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/32
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/33
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/34
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/35
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/36
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/37
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/38
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
undo dot1x handshake
dot1x
#
interface GigabitEthernet1/0/39
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/40
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/41
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/42
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/43
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/44
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/45
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/46
port access vlan 10
stp edged-port enable
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/47
port link-type trunk
port trunk permit vlan all
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/48
port link-type trunk
port trunk permit vlan all
mac-authentication
mac-authentication timer auth-delay 30
dot1x
#
interface GigabitEthernet1/0/49
port link-type trunk
port trunk permit vlan all
port link-aggregation group 1
#
interface GigabitEthernet1/0/50
port link-type trunk
port trunk permit vlan all
port link-aggregation group 1
#
interface GigabitEthernet1/0/51
port link-type trunk
port trunk permit vlan all
port link-aggregation group 1
#
interface GigabitEthernet1/0/52
port link-type trunk
port trunk permit vlan all
port link-aggregation group 1
#
ip route-static 0.0.0.0 0.0.0.0 192.168.100.2
#
undo info-center logfile enable
#
snmp-agent
snmp-agent local-engineid 383030303633413236353133443436314645433741334635
snmp-agent community read public
snmp-agent community write private
snmp-agent sys-info version v2c
snmp-agent target-host trap address udp-domain 10.192.1.166 params securityname public v2c
snmp-agent target-host trap address udp-domain 10.192.51.105 params securityname public v2c
#
ntp-service unicast-server 10.192.1.152
#
load xml-configuration
#
user-interface aux 0
authentication-mode scheme
user-interface vty 0 4
acl 2110 inbound
authentication-mode scheme
protocol inbound telnet
user-interface vty 5 15
authentication-mode scheme
#
return
(0)
最佳答案
· macAddressOrUserLoginSecure
端口同时处于userLoginSecure模式和macAddressWithRadius模式,且允许一个802.1X认证用户及多个MAC地址认证用户接入。
此模式下,802.1X认证优先级大于MAC地址认证:报文首先触发802.1X认证,默认情况下,如果802.1X认证失败再进行MAC地址认证;若开启了端口的MAC地址认证和802.1X认证并行处理功能,则端口配置了802.1X单播触发功能的情况下,当端口收到源MAC地址未知的报文,会向该MAC地址单播发送EAP-Request帧来触发802.1X认证,但不等待802.1X认证处理完成,就同时进行MAC地址认证。
· macAddressOrUserLoginSecureExt
与macAddressOrUserLoginSecure类似,但允许端口下有多个802.1X和MAC地址认证用户。
· macAddressElseUserLoginSecure
端口同时处于macAddressWithRadius模式和userLoginSecure模式,但MAC地址认证优先级大于802.1X认证。允许端口下一个802.1X认证用户及多个MAC地址认证用户接入。
非802.1X报文直接进行MAC地址认证。802.1X报文先进行MAC地址认证,如果MAC地址认证失败再进行802.1X认证。
· macAddressElseUserLoginSecureExt
与macAddressElseUserLoginSecure类似,但允许端口下有多个802.1X和MAC地址认证用户。
(0)
所以终端设备是要认证两次才能上网是吧?先认证802.1x再认证MAC地址?
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
所以终端设备是要认证两次才能上网是吧?先认证802.1x再认证MAC地址?