一、配置Radius服務(wù)
#
radius scheme mac
primary authentication 10.113.33.51
primary accounting 10.113.33.51
key authentication cipher $c$3$bRJa6YzQFJI9oOqIoiChKe+U3HOXSkeOWg==
key accounting cipher $c$3$uqqzN2cwKT7bX1DRIgLJtMb5RwrjEs4uTw==
user-name-format without-domain
nas-ip 10.112.254.98
#
二抹竹、配置Domain域
#? ? ? ? ? ? ?
domain mac
authentication lan-access radius-scheme mac
authorization lan-access radius-scheme mac
accounting lan-access radius-scheme mac
#
三膜楷、全局使能dot1x認(rèn)證
#
dot1x
#
四柴底、配置MAC地址認(rèn)證用戶名格式:使用帶連字符的MAC地址作為用戶名與密碼陋守,其中字母小寫
#
mac-authentication user-name-format mac-address with-hyphen lowercase
#
五、服務(wù)模板配置dot1x+MAC認(rèn)證
#
wlan service-template 1
ssid dot1x&mac
client-security authentication-mode mac-then-dot1x? ? //表示先進(jìn)行MAC地址認(rèn)證捅膘,如果失敗翘地,再進(jìn)行802.1X認(rèn)證申尤。如果認(rèn)證成功,則不進(jìn)行802.1X認(rèn)證衙耕。
dot1x domain imc? ?
mac-authentication domain imc
service-template enable
#