二、交换机配置
2.1 基础配置。
vlan 10
name Office
#
vlan 20
name Guest
#
vlan 30
name Critical
#
vlan 100
name Con_To_AC
#
dhcp server ip-pool vlan10
gateway-list 192.168.10.1
network 192.168.10.0 mask 255.255.255.0
dns-list 218.85.157.99
#
dhcp server ip-pool vlan20
gateway-list 192.168.20.1
network 192.168.20.0 mask 255.255.255.0
dns-list 218.85.157.99
#
dhcp server ip-pool vlan30
gateway-list 192.168.30.1
network 192.168.30.0 mask 255.255.255.0
dns-list 218.85.157.99
#
interface Vlan-interface10
ip address 192.168.10.1 255.255.255.0
dhcp server apply ip-pool vlan10
#
interface Vlan-interface20
ip address 192.168.20.1 255.255.255.0
dhcp server apply ip-pool vlan20
#
interface Vlan-interface30
ip address 192.168.30.1 255.255.255.0
dhcp server apply ip-pool vlan30
#
interface Vlan-interface100
ip address 10.252.251.1 255.255.255.0
#
interface GigabitEthernet1/0/1
port link-mode bridge
port access vlan 100
2.2 配置snmp
snmp-agent
snmp-agent community read simple sangfor
snmp-agent sys-info version v2c
2.3 配置radius服务器信息、ISP域
radius scheme sangfor_rd
primary authentication 10.252.251.251
primary accounting 10.252.251.251
key authentication simple sangfor
key accounting simple sangfor
user-name-format without-domain
#
domain name sangfor_ad
authentication lan-access radius-scheme sangfor_rd
authorization lan-access radius-scheme sangfor_rd
accounting lan-access radius-scheme sangfor_rd
#
domain default enable sangfor_ad
2.4 配置dot1x(portbased)
dot1x
dot1x authentication-method eap
#
interface GigabitEthernet1/0/2
port link-mode bridge
dot1x
dot1x mandatory-domain sangfor_ad
dot1x port-method portbased
dot1x guest-vlan 20
dot1x critical vlan 30
#
三、全网AC配置
3.1 配置IP、路由(略)
3.2 配置跨三层取mac
3.3配置802.1x接入认证
vlan关联用户
3.4添加用户
四、验证
4.1 客户端认证前
交换机自动将接口划入vlan20,并且终端可以正常获取vlan20的ip地址。
4.2客户端认证后
使用iNode客户端进行802.1x认证(没开准入模块序列号)
交换机自动将接口划入vlan10
客户端获取到vlan10的地址
在AC上能看到用户在线(IP会显示错误,因为不是使用认证助手,iNode的ip上报机制无法上报到AC)
4.3 AC故障测试
AC上关闭802.1x接入认证(或者点开启逃生功能)
终端无法认证成功
交换机将端口划入vlan30
终端获取到vlan30的地址
PS:如果接入方式使用macbased,需要全局开启mac认证,并且接口配置改为:
interface GigabitEthernet1/0/2
port link-type hybrid
undo port hybrid vlan 1
port hybrid vlan 10 20 30 untagged
mac-vlan enable
dot1x
dot1x mandatory-domain sangfor_ad
dot1x guest-vlan 20
dot1x critical vlan 30
mac-authentication
模拟器无法实现mac-vlan(命令能敲,没效果),需用真机!!!!