H3C WAC360 based on Win2012 NPS 802.1x authentication
1: H3C WAC360 configuration
Radius scheme radius primary authentication 192.168.90.12 key authentication simple 123123 user-name-format without-domaindomain radius authentication lan-access radius-scheme radius authorization lan-access radius-scheme radius access-limit disable state active idle-cut disable self-service-url disable wlan service-template 4 crypto ssid Office WiFi bind WLAN-ESS3 cipher-suite ccmp security-ie rsn service-template enableinterface WLAN-ESS3 port link-type hybrid port hybrid vlan 1 10 untagged port hybrid pvid vlan 10 mac-vlan enable port-security port-mode userlogin-secure-ext port-security Tx-key-type 11key undo dot1x handshake dot1x mandatory-domain radius mac-authentication domain system dot1x authentication-method eap
2:win2012 NPS configuration
Add a network policy directly
Strategy 1: conditional Machine Groups and NAS Port Type others can default
Strategy 2: conditional User Groups and NAS Port Type others can default
In the latter authentication method, EAP directly. The following security ticks are related to CHAP.
Add a NPS client with the IP address of AC, and the key should be the same as that of h4c