Mục tiêu thực hành:
- Cấu hình xác thực 802.1X trên RADIUS Authenticator (SW3750G).
- Khảo sát log xác thực trên RADIUS Authenticator (SW3750G).
- Khảo sát log xác thực trên RADIUS Server (Cisco ISE).
Các bước triển khai:
Cấu hình xác thực 802.1X trên RADIUS Authenticator (SW3750G).
ip routinginterface vlan 1ip address 172.16.31.201 255.255.255.0no shutdownexitip route 0.0.0.0 0.0.0.0 172.16.31.4interface g2/0/24switchport mode accessswitchport access vlan 1spanning-tree portfastexit
aaa new-modelaaa authentication dot1x default group radiusradius-server host 192.168.200.252 key buiphamdot1x system-auth-controlinterface GigabitEthernet2/0/1switchport mode accessauthentication port-control autodot1x pae authenticatorspanning-tree portfastexit
- Kiểm tra thông tin xác thực Username & Password có hợp lệ hay không trên Switch 3750.
SW3750G# test aaa group radius StaffUser01 Admin@2021 new-code
Khảo sát log xác thực trên RADIUS Authenticator (SW3750G).
SW3750G#*Mar 1 01:21:12.657: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet2/0/1, changed state to down*Mar 1 01:21:13.663: %LINK-3-UPDOWN: Interface GigabitEthernet2/0/1, changed state to down*Mar 1 01:21:16.205: %AUTHMGR-5-START: Starting 'dot1x' for client (80ce.6282.7f9f) on Interface Gi2/0/1 AuditSessionID AC101FC900000004004A666E*Mar 1 01:21:17.891: %LINK-3-UPDOWN: Interface GigabitEthernet2/0/1, changed state to up*Mar 1 01:21:28.092: %DOT1X-5-SUCCESS: Authentication successful for client (80ce.6282.7f9f) on Interface Gi2/0/1 AuditSessionID*Mar 1 01:21:28.092: %AUTHMGR-7-RESULT: Authentication result 'success' from 'dot1x' for client (80ce.6282.7f9f) on Interface Gi2/0/1 AuditSessionID AC101FC900000004004A666E*Mar 1 01:21:29.107: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet2/0/1, changed state to up*Mar 1 01:21:29.123: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (80ce.6282.7f9f) on Interface Gi2/0/1 AuditSessionID AC101FC900000004004A666ESW3750G#
SW3750G# show authentication sessionsInterface MAC Address Method Domain Status Session IDGi2/0/1 80ce.6282.7f9f dot1x DATA Authz Success AC101FC900000004004A666ESW3750G#
SW3750G# show authentication sessions interface g2/0/1Interface: GigabitEthernet2/0/1MAC Address: 80ce.6282.7f9fIP Address: UnknownUser-Name: StaffUser01Status: Authz SuccessDomain: DATASecurity Policy: Should SecureSecurity Status: UnsecureOper host mode: single-hostOper control dir: bothAuthorized By: Authentication ServerVlan Group: N/ASession timeout: N/AIdle timeout: N/ACommon Session ID: AC101FC900000004004A666EAcct Session ID: 0x00000007Handle: 0x5B000004Runnable methods list:Method Statedot1x Authc SuccessSW3750G#
Công ty DWN (Đại lý cấp I Cisco Meraki tại Việt Nam) cung cấp dịch vụ tư vấn, báo giá, phân phối và triển khai các giải pháp liên quan đến:
- WiFi (Cisco Meraki, Aruba, Ruckus)
- Firewall (Cisco ASA, Fortinet, WatchGuard, PaloAlto)
- Network (Cisco vs HP Router & Switch)
Liên hệ với Bùi Phạm để biết thêm thông tin chi tiết.
0 comments