用VLAN做端口隔离和dot1.x认证

来源:互联网 发布:中美网络红黑大战 编辑:程序博客网 时间:2024/04/28 10:32

radius服务器配置

radius scheme system
 server-type huawei
 primary authentication 127.0.0.1 1645
 primary accounting 127.0.0.1 1646
 user-name-format without-domain
radius scheme huawei
 server-type huawei
 primary authentication 10.1.17.14 1812
 primary accounting 10.1.17.14 1813
 key authentication cams
 key accounting cams
 user-name-format without-domain
 security-policy-server 10.1.17.14

domain huawei
 radius-scheme huawei
 access-limit disable
 state active
 vlan-assignment-mode integer
 idle-cut disable
 self-service-url disable
 messenger time disable

domain system
 radius-scheme system
 access-limit disable
 state active
 vlan-assignment-mode integer
 idle-cut disable
 self-service-url disable
 messenger time disable

 domain default enable huawei  //把华为的RADIUS设为默认的RADIUS

开启全局的dot1x

 dot1x
 dot1x supp-proxy-check trap
 dot1x supp-proxy-check logoff

划分多个VLAN并配置管理IP地址

vlan 1
#
vlan 4
#
vlan 6
#
vlan 10
#
vlan 1001
#
vlan 1002
#
vlan 1003
#
vlan 1004
#
vlan 1005
#
vlan 1006
#
vlan 1007
#
vlan 1008
#
vlan 1009
#
vlan 1010
#
vlan 1011
#
vlan 1012
#
vlan 1013
#
vlan 1014
#
vlan 1015
#
vlan 1016
#
vlan 1017
#
vlan 1018
#
vlan 1019
#
vlan 1020
#
vlan 1021
#
vlan 1022
#
vlan 1023
#
vlan 1024
#
vlan 1025
#
vlan 1026
#
vlan 1027
#
vlan 1028
#
vlan 1029
#
vlan 1030
#
vlan 1031
#
vlan 1032
#
vlan 1033
#
vlan 1034
#
vlan 1035
#
vlan 1036
#
vlan 1037
#
vlan 1038
#
vlan 1039
#
vlan 1040
#
vlan 1041
#
vlan 1042
#
vlan 1043
#
vlan 1044
#
vlan 1045
#
vlan 1046
#
vlan 1047
#
vlan 1048
#
interface Vlan-interface10
 ip address X.X.X.X 255.255.255.0

端口配置信息

#
interface Ethernet0/1
 port link-type hybrid
 port hybrid vlan 1 1001 untagged
 port hybrid pvid vlan 1001
 broadcast-suppression 5
 dot1x
 dot1x supp-proxy-check trap
 dot1x supp-proxy-check logoff
 dot1x version-check
#
interface Ethernet0/2
 port link-type hybrid
 port hybrid vlan 1 1002 untagged
 port hybrid pvid vlan 1002
 broadcast-suppression 5
 dot1x
 dot1x supp-proxy-check trap
 dot1x supp-proxy-check logoff
 dot1x version-check

....................

配置上行口信息

interface GigabitEthernet2/1
 port link-type hybrid
 port hybrid vlan 4 10 tagged
 port hybrid vlan 1 6 1001 to 1048 untagged
 broadcast-suppression 5

配置与其连接的上层交换机的下行口信息

 speed 1000
 port link-type hybrid
 port hybrid vlan 4 10 tagged
 port hybrid vlan 1 untagged
 broadcast-suppression 5
 description toXXX

 

 

原创粉丝点击