Setting radius parameters – Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 181

Advertising
background image

Dynamic VLAN assignment for 802.1X port configuration

on page 184 (optional)

Dynamically applying IP ACLs and MAC address filtersto 802.1X ports

on page 187

2. Configure the device role as the Authenticator:

Enabling 802.1X port security

on page 191

Initializing 802.1X on a port

on page 195 (optional)

3. Configure the device interaction with Clients:

Configuring periodic re-authentication

on page 192 (optional)

Re-authenticating a port manually

on page 192 (optional)

Setting the quiet period

on page 193 (optional)

Setting the wait interval for EAP frame retransmissions

on page 193 (optional)

Setting the maximum number of EAP frame retransmissions

on page 193 (optional)

Specifying a timeout for retransmission of messages to the authentication server

on page

195 (optional)

Allowing access to multiple hosts

on page 195 (optional)

MAC address filters for EAP frames

on page 198 (optional)

Configuring an authentication method list for 802.1X

To use 802.1X port security, you must specify an authentication method to be used to authenticate
Clients. Brocade supports RADIUS authentication with 802.1X port security. To use RADIUS
authentication with 802.1X port security, you create an authentication method list for 802.1X and specify
RADIUS as an authentication method, then configure communication between the Brocade device and
RADIUS server.

Brocade(config)#aaa authentication dot1x default radius

Syntax: [no] aaa authentication dot1x default method-list

For the method-list , enter at least one of the following authentication methods

radius - Use the list of all RADIUS servers that support 802.1X for authentication.

none - Use no authentication. The Client is automatically authenticated by other means, without the
device using information supplied by the Client.

NOTE
If you specify both radius and none , make sure radius comes before none in the method list.

Setting RADIUS parameters

To use a RADIUS server to authenticate access to a Brocade device, you must identify the server to the
Brocade device.

device(config)#radius-server host 10.157.22.99 auth-port 1812 acct-port 1813

default key mirabeau dot1x

Syntax: radius-server { hostip-addr | ipv6-addr | server-name } [ auth-port num | acct-port num |
default ] [ key {0 | 2 } string ] [ dot1x ]

The host ip-addr , ipv6-addr or server-name parameters are either an IP address or an ASCII text string.

Configuring an authentication method list for 802.1X

FastIron Ethernet Switch Security Configuration Guide

181

53-1003088-03

Advertising