Huawei dot1x certification test configuration
[NW_HJ_NACC_5F-3_S3700] d cu
#
! Software Version V100R006C03
Sysname NW_HJ_NACC_5F-3_S3700
#
Info-center source default channel 0 trap state off level warning
#
Vlan batch 9 to 11 999
#
Domain radius
#
Dot1x enable
Dot1x authentication-method eap
#
Http server load flash:/s3700-52p-ei-v100r006c03.web.zip
#
Radius-server template dot1xserver
Radius-server shared-key cipher% $% $VcUC) ROF "+ 1 [Y03TVe6OAh _ V% OAh% $
Radius-server authentication 10.209.2.10 1812
Radius-server authentication 10.209.2.11 1812 secondary
Radius-server accounting 10.209.2.10 1813
Radius-server accounting 10.209.2.11 1813 secondary
Radius-server retransmit 2
#
Acl number 2001
Rule 1 permit source 10.211.2.209 0
Rule 2 permit source 10.211.2.248 0
Rule 3 permit source 10.209.58.137 0
Rule 4 permit source 10.209.58.132 0
Rule 5 permit source 10.209.45.210 0
Rule 6 permit source 10.209.58.65 0
Rule 7 permit source 10.209.5.30 0
Rule 10 deny
#
Aaa
Authentication-scheme default
Authentication-scheme dot1xscheme
Authentication-mode radius
Authorization-scheme default
Accounting-scheme default
Accounting-scheme dot1xscheme
Accounting-mode radius
Domain default
Domain default_admin
Domain radius
Authentication-scheme dot1xscheme
Accounting-scheme dot1xscheme
Radius-server dot1xserver
Local-user admin password cipher% $% $XI] R% H] CF4be-VK0MiqCSXOF%$%$
Local-user admin privilege level 15
Local-user admin service-type ssh http
#
Interface Vlanif1
#
Interface Vlanif999
Ip address 10.209.13.212 255.255.255.224
#
Interface Ethernet0/0/1
Port link-type access
Port default vlan 9
#
Interface Ethernet0/0/2
Port link-type access
Port default vlan 9
#
Interface Ethernet0/0/3
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/4
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/5
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/6
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/7
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/8
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/9
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/10
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/11
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/12
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/13
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/14
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/15
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/16
Port link-type access
Port default vlan 10
Dot1x enable
#
Interface Ethernet0/0/17
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/18
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/19
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/20
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/21
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/22
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/23
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/24
Port link-type access
Port default vlan 10
#
Interface Ethernet0/0/25
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/26
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/27
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/28
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/29
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/30
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/31
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/32
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/33
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/34
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/35
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/36
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/37
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/38
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/39
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/40
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/41
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/42
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/43
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/44
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/45
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/46
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/47
Port link-type access
Port default vlan 11
#
Interface Ethernet0/0/48
Port link-type trunk
Port trunk allow-pass vlan 2 to 4094
#
Interface GigabitEthernet0/0/1
Port link-type trunk
Port trunk allow-pass vlan 2 to 4094
Undo negotiation auto
#
Interface GigabitEthernet0/0/2
Port link-type trunk
Port trunk allow-pass vlan 2 to 4094
Undo negotiation auto
#
Interface GigabitEthernet0/0/3
Port link-type trunk
Port trunk allow-pass vlan 2 to 4094
Undo negotiation auto
#
Interface GigabitEthernet0/0/4
Port link-type trunk
Port trunk allow-pass vlan 2 to 4094
Undo negotiation auto
#
Interface NULL0
#
Ip route-static 0.0.0.0 0.0.0.0 10.209.13.193
#
Snmp-agent
Snmp-agent local-engineid 000007DB7F000001000071D1
Snmp-agent community read cipher% $% $8-AMBL6OG=K-Fw.T6m [JTwne%$%$ acl 2001
Snmp-agent community read cipher $$vGtCA.dI8L (I) ROM3g$&+MD;%$%$
Snmp-agent community read cipher $dE,u (g] xgY) cG {7'bmaL+2)} $$
Snmp-agent sys-info version all
#
Stelnet server enable
Ssh user admin
Ssh user admin authentication-type password
Ssh user admin service-type all
#
User-interface con 0
Authentication-mode password
Set authentication password cipher $$BW2U9\ anMA