交换机802.1x逃生模式

一、华三

1.1 方式一

radius scheme dot1x
 primary authentication 172.16.100.41
 key authentication simple admin@123
 user-name-format without-domain
#
domain dot1x
 authentication lan-access radius-scheme dot1x none   //加个none
 authorization lan-access none
 accounting lan-access none
#
 dot1x
 dot1x authentication-method eap

1.2 方式二

#接口下配置,逃生vlan
#
interface GigabitEthernet1/0/2
 dot1x critical vlan 10
 dot1x critical eapol

二、华为

2.1 传统模式方式一

通过修改认证方式,传统模式和统一模式都可以实现

#
aaa
 authentication-scheme dot1x
  authentication-mode radius none

2.2 传统模式方式二

interface GigabitEthernet1/0/2
 authentication critical-vlan 10          
 authentication critical eapol-success

2.3 统一模式方式二

#
acl number 3000
 rule 5 permit ip
#
aaa
 service-scheme help
  acl-id 3000
#
authentication-profile name dot1x
 authentication event authen-server-down action authorize service-scheme help
 authentication event authen-server-up action re-authen

发表回复