用户操作
[即时聊天] [发私信] [加为好友]
张德锋ID:deflag
30931次访问,排名3981,好友21人,关注者27人。
从事于IT业,爱好篮球,专职于网络技术.
好尝试新鲜事物.
deflag的文章
原创 53 篇
翻译 0 篇
转载 9 篇
评论 25 篇
张德锋的公告
和大家一起学习进步。 Locations of visitors to this page 有事就Q我!
最近评论
逆援助大好き:人妻セフレナンパ
deflag:你的IAS报什么错了呢?
deflag:你的IAS报什么错了呢?
deflag:你的IAS报什么错了呢?
deflag:你的IAS报什么错了呢?
文章分类
收藏
    相册
    hometown
    friend
    IT技术
    eskystar
    PHP
    DoNews.Com
    php中国官方
    php官方网站
    vc++
    VCHelp
    VCKBase
    存档
    软件项目交易
    订阅我的博客
    XML聚合  FeedSky
    订阅到鲜果
    订阅到Google
    订阅到抓虾
    订阅到BlogLines
    订阅到Yahoo
    订阅到GouGou
    订阅到飞鸽
    订阅到Rojo
    订阅到newsgator
    订阅到netvibes

    原创 H3C交换机 802.1X+AD+CA+IAS进行RADIUS身份验证 收藏

    新一篇: 解放日报:“爱国病毒”与“谢谢中国”哪个更可怕 | 旧一篇: Cisco 2950G 802.1X+AD+CA+IAS进行RADIUS身份验证

    环境与要求都和上一篇<<Cisco 2950G 802.1X+AD+CA+IAS进行RADIUS身份验证 >>一样,只是交换机的配置文件不同.现在将H3C交换机的802.1x配置文件贴出来:

    <layer_2_3>dis cu
    #
     sysname layer_2_3
    #
     domain default enable autonavi.com
    #
     loopback-detection enable
    #
     gvrp
    #
     dot1x
     dot1x authentication-method eap
    #
    radius scheme system
    radius scheme test
     server-type standard
     primary authentication 192.168.0.2

     accounting optional
     key authentication test
    #
    domain test.com
     scheme radius-scheme test
     vlan-assignment-mode string
    domain system
    #                                         
     stp enable
    #
    #
    vlan 1
    #
    vlan 3
    #
    vlan 6
    #
    vlan 7
    name test
    #
    vlan 21
    #                                        
    interface Vlan-interface1
     ip address 192.168.0.1 255.255.255.0
    #
    interface Vlan-interface6
    #
    interface Vlan-interface7
    #
    interface Aux1/0/0
    #
    interface Ethernet1/0/1
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/2
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/3
     broadcast-suppression 40
     dot1x port-method portbased
     dot1x guest-vlan 21
     dot1x

    #
    interface Ethernet1/0/4                  
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/5
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/6
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/7
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/8
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/9
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/10                 
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/11
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/12
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/13
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/14
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/15
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/16                 
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/17
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/18
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/19
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/20
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/21
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/22                 
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/23
     broadcast-suppression 40
     port access vlan 3
    #
    interface Ethernet1/0/24
     broadcast-suppression 40
     port access vlan 3
    #
    interface GigabitEthernet1/1/1
     port link-type trunk
     port trunk permit vlan all
     broadcast-suppression 40
     gvrp
    #
    interface GigabitEthernet1/1/2
     port link-type trunk
     port trunk permit vlan all
     broadcast-suppression 40
    #
    interface GigabitEthernet1/1/3
     port link-type trunk                    
     port trunk permit vlan all
     broadcast-suppression 40
     gvrp
    #
    interface GigabitEthernet1/1/4
     broadcast-suppression 40
     port access vlan 3
    #
     undo irf-fabric authentication-mode
    #
    interface NULL0
    #
     voice vlan mac-address 0001-e300-0000 mask ffff-ff00-0000
    #
    #
    #
    user-interface aux 0 7
    user-interface vty 1 4                   
    #
    return

    发表于 @ 2007年10月16日 11:18:00|评论(loading...)|编辑

    新一篇: 解放日报:“爱国病毒”与“谢谢中国”哪个更可怕 | 旧一篇: Cisco 2950G 802.1X+AD+CA+IAS进行RADIUS身份验证

    评论:没有评论。

    发表评论  


    登录
    Csdn Blog version 3.1a
    Copyright © 张德锋