Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Huawei dot1x certification test configuration

Shulou Source: shulou.com Published: 2022-06-01 03:29:44 10月01日 Update

[NW_HJ_NACC_5F-3_S3700] d cu

#

! Software Version V100R006C03

Sysname NW_HJ_NACC_5F-3_S3700

#

Info-center source default channel 0 trap state off level warning

#

Vlan batch 9 to 11 999

#

Domain radius

#

Dot1x enable

Dot1x authentication-method eap

#

Http server load flash:/s3700-52p-ei-v100r006c03.web.zip

#

Radius-server template dot1xserver

Radius-server shared-key cipher% $% $VcUC) ROF "+ 1 [Y03TVe6OAh _ V% OAh% $

Radius-server authentication 10.209.2.10 1812

Radius-server authentication 10.209.2.11 1812 secondary

Radius-server accounting 10.209.2.10 1813

Radius-server accounting 10.209.2.11 1813 secondary

Radius-server retransmit 2

#

Acl number 2001

Rule 1 permit source 10.211.2.209 0

Rule 2 permit source 10.211.2.248 0

Rule 3 permit source 10.209.58.137 0

Rule 4 permit source 10.209.58.132 0

Rule 5 permit source 10.209.45.210 0

Rule 6 permit source 10.209.58.65 0

Rule 7 permit source 10.209.5.30 0

Rule 10 deny

#

Aaa

Authentication-scheme default

Authentication-scheme dot1xscheme

Authentication-mode radius

Authorization-scheme default

Accounting-scheme default

Accounting-scheme dot1xscheme

Accounting-mode radius

Domain default

Domain default_admin

Domain radius

Authentication-scheme dot1xscheme

Accounting-scheme dot1xscheme

Radius-server dot1xserver

Local-user admin password cipher% $% $XI] R% H] CF4be-VK0MiqCSXOF%$%$

Local-user admin privilege level 15

Local-user admin service-type ssh http

#

Interface Vlanif1

#

Interface Vlanif999

Ip address 10.209.13.212 255.255.255.224

#

Interface Ethernet0/0/1

Port link-type access

Port default vlan 9

#

Interface Ethernet0/0/2

Port link-type access

Port default vlan 9

#

Interface Ethernet0/0/3

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/4

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/5

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/6

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/7

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/8

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/9

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/10

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/11

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/12

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/13

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/14

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/15

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/16

Port link-type access

Port default vlan 10

Dot1x enable

#

Interface Ethernet0/0/17

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/18

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/19

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/20

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/21

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/22

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/23

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/24

Port link-type access

Port default vlan 10

#

Interface Ethernet0/0/25

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/26

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/27

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/28

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/29

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/30

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/31

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/32

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/33

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/34

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/35

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/36

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/37

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/38

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/39

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/40

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/41

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/42

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/43

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/44

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/45

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/46

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/47

Port link-type access

Port default vlan 11

#

Interface Ethernet0/0/48

Port link-type trunk

Port trunk allow-pass vlan 2 to 4094

#

Interface GigabitEthernet0/0/1

Port link-type trunk

Port trunk allow-pass vlan 2 to 4094

Undo negotiation auto

#

Interface GigabitEthernet0/0/2

Port link-type trunk

Port trunk allow-pass vlan 2 to 4094

Undo negotiation auto

#

Interface GigabitEthernet0/0/3

Port link-type trunk

Port trunk allow-pass vlan 2 to 4094

Undo negotiation auto

#

Interface GigabitEthernet0/0/4

Port link-type trunk

Port trunk allow-pass vlan 2 to 4094

Undo negotiation auto

#

Interface NULL0

#

Ip route-static 0.0.0.0 0.0.0.0 10.209.13.193

#

Snmp-agent

Snmp-agent local-engineid 000007DB7F000001000071D1

Snmp-agent community read cipher% $% $8-AMBL6OG=K-Fw.T6m [JTwne%$%$ acl 2001

Snmp-agent community read cipher $$vGtCA.dI8L (I) ROM3g$&+MD;%$%$

Snmp-agent community read cipher $dE,u (g] xgY) cG {7'bmaL+2)} $$

Snmp-agent sys-info version all

#

Stelnet server enable

Ssh user admin

Ssh user admin authentication-type password

Ssh user admin service-type all

#

User-interface con 0

Authentication-mode password

Set authentication password cipher $$BW2U9\ anMA

Tags: Huawei testing authentication configuration Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Redmi Xiaomi vpn Shulou Tech Info Huawei