参考:https://search.ruijie.com.cn:3014/api/anno/short/url/M7Fzmaa
交换机配置802.1x认证(dot1x认证)
锐捷RGOS非10.X平台配置步骤:
1、全局配置dot1x
Ruijie>enable
Ruijie#configure terminal
Ruijie(config)# aaa authentication dot1x ------>打开802.1x
Ruijie(config)#radius-server host 192.168.5.183 ------>配置认证服务器IP地址
Ruijie(config)#radius-server key ruijie ------>配置认证服务器的key为test字符串
Ruijie(config)#aaa accounting server 192.168.5.100 ----指定记帐服务器地址
Ruijie(config)#aaa accounting ------>打开计费
Ruijie(config)#aaa accounting update ------>开启记费更新
Ruijie(config)#snmp-server community ruijie rw ------>配置snmp属性值为ruijie,并赋予读写权限
2、接口下开启dot1x功能
Ruijie(config)# interface FastEthernet 0/1
Ruijie(config-if)# dot1x port-control auto
3、保存配置
Ruijie(config-if)# end
Ruijie#write ------>确认配置正确,保存配置
非10.X验证
Ruijie#sho dot1x ---->查看802.1x 配置
IEEE 802.1X Status : Disabled
Authentication mode : EAP-MD5
Authentication user number : 0
Current user number : 0
radius server fail : No
reauth-enabled : Disabled
reauth-period : 3600
quiet-period : 10
tx-period : 3
supp-timeout : 3
server-timeout : 3
reauth-max : 2
max-req : 1
dot1x accout-update-interval : 900
filter-nonRG-su : Disable
server-retry-max : 20
client probe : Disabled
eapol-tag : Disabled
Ruijie#show dot1x summary --------->查看用户认证状态信息
ID MAC Interface VLAN Auth-State Backend-State Port-Status User-Type
-------- -------------- --------- ---- --------------- ------------- ----------- ---------
Ruijie#sho dot1x port-control -------->查看接口是否开启dot1x功能
Ports Status
-------------------- ----------
Fa0/1 Enabled ----->enable表示开启了dot1.x
Fa0/2 Disabled
Fa0/3 Disabled
【交换机】全局radius逃生功能实现radius-server不可用时的免认证
aaa new-model
aaa accounting update periodic 15
aaa accounting update
aaa accounting network ruijie start-stop group radius
aaa authentication dot1x ruijie group radius none
radius-server host 192.168.33.238
radius-server timeout 2
radius-server retransmit 2
radius-server key ruijie
dot1x accounting ruijie
dot1x authentication ruijie
ip default-gateway 192.168.33.1
interface VLAN 1
ip address 192.168.33.196 255.255.255.0
no shutdown
interface FastEthernet 0/24
dot1x port-control auto
//对timeout*retransmit(重新传输)有要求,必须小于dot1x timeout server-timeout,否则逃生功能不生效。