Hiện tại em đang triển khai 802.1x với mô hình:
Client XP-----SW 2960------IAS
Hiện tại là xác thực từ SW với IAS thì OK rồi ví dụ phía dưới:
--------------------
SW-CNTT04#test aaa group radius test1 123456a@ legacy
Attempting authentication test to server-group radius using radius
User was successfully authenticated.
SW-CNTT04#
015057: *Apr 24 18:10:54.376: AAA: parse name=<no string> idb type=-1 tty=-1
015058: *Apr 24 18:10:54.376: AAA/MEMORY: create_user (0x2BC897C) user='test1' ruser='NULL' ds0=0 port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)
015059: *Apr 24 18:10:54.376: RADIUS: Pick NAS IP for u=0x2BC897C tableid=0 cfg_addr=0.0.0.0
015060: *Apr 24 18:10:54.376: RADIUS: ustruct sharecount=1
015061: *Apr 24 18:10:54.376: Radius: radius_port_info() success=0 radius_nas_port=1
015062: *Apr 24 18:10:54.376: RADIUS/ENCODE: Best Local IP-Address 10.4.20.244 for Radius-Server 10.4.29.18
015063: *Apr 24 18:10:54.376: RADIUS(00000000): Send Access-Request to 10.4.29.18:1812 id 1645/71, len 57
015064: *Apr 24 18:10:54.376: RADIUS: authenticator F9 E5 1A 6C B3 41 6A 0E - EE 03 DF 33 BA 31 45 94
015065: *Apr 24 18:10:54.376: RADIUS: NAS-IP-Address [4] 6 10.4.20.244
015066: *Apr 24 18:10:54.384: RADIUS: NAS-Port-Type [61] 6 Async [0]
015067: *Apr 24 18:10:54.384: RADIUS: User-Name [1] 7 "test1"
015068: *Apr 24 18:10:54.384: RADIUS: User-Password [2] 18 *
015069: *Apr 24 18:10:54.384: RADIUS: Received from id 1645/71 10.4.29.18:1812, Access-Accept, len 74
015070: *Apr 24 18:10:54.384: RADIUS: authenticator D4 EF 15 40 36 AB 69 A2 - FC F8 0F 7B 24 14 4B D0
015071: *Apr 24 18:10:54.384: RADIUS: Service-Type [6] 6 Framed [2]
015072: *Apr 24 18:10:54.384: RADIUS: Tunnel-Medium-Type [65] 6 00:ALL_802 [6]
015073: *Apr 24 18:10:54.384: RADIUS: Tunnel-Private-Group[81] 4 "29"
015074: *Apr 24 18:10:54.384: RADIUS: Tunnel-Type [64] 6 00:VLAN [13]
015075: *Apr 24 18:10:54.384: RADIUS: Class [25] 32
015076: *Apr 24 18:10:54.384: RADIUS: 2B 43 03 59 00 00 01 37 00 01 0A 04 1D 12 01 C6 0F 77 08 A7 49 86 00 00 00 00 00 00 00 17 [ +CY7wI]
015077: *Apr 24 18:10:54.384: RADIUS: saved authorization data for user 2BC897C at 1F91900
015078: *Apr 24 18:10:54.384: AAA/MEMORY: free_user (0x2BC897C) user='test1' ruser='NULL' port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 vrf= (id=0)
--------------------------------
Cấu hình SW của em đây ạ:
SW-CNTT04#show run
Building configuration...
Current configuration : 10063 bytes
!
version 12.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
service sequence-numbers
!
hostname SW-CNTT04
!
boot-start-marker
boot-end-marker
!
enable password 7 02150C5903094C010D4F0D140C19
!
username anhnc privilege 2 password 7 104D000A0618
username shb-admin privilege 15 password 7 14041A09040B690B652937382B1D
username cisco privilege 2 password 7 030752180500
aaa new-model
!
!
aaa authentication login default local
aaa authentication dot1x default group radius
aaa authorization exec default local
aaa authorization network default group radius
!
!
!
aaa session-id common
system mtu routing 1500
ip subnet-zero
!
!
!
crypto pki trustpoint TP-self-signed-4276715776
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-4276715776
revocation-check none
rsakeypair TP-self-signed-4276715776
!
!
crypto pki certificate chain TP-self-signed-4276715776
certificate self-signed 01
30820242 308201AB A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 34323736 37313537 3736301E 170D3933 30333031 30303030
35335A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D34 32373637
31353737 3630819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100C42F D1F3682C 7649FDD8 30364D6F B5AB4B82 80E9CFC1 75195E23 FC2F72F4
F1386C3C 63107A63 F97ECAE4 A37EFA53 050D9076 2EEB6660 0190A028 616A8E82
CB8DE052 429A943E 6ACF87F0 CD42ADCE 324BFAF8 953ED848 81392727 8FB03F00
43A7B0D1 B45105AD C0EDD026 64EE6769 12A445B9 DDCCA505 0D32DE9B F4F4F81D
3D0B0203 010001A3 6A306830 0F060355 1D130101 FF040530 030101FF 30150603
551D1104 0E300C82 0A53572D 434E5454 30342E30 1F060355 1D230418 30168014
A7828EC1 8213C249 919F6C41 AFBDF9F4 AB3BEFDB 301D0603 551D0E04 160414A7
828EC182 13C24991 9F6C41AF BDF9F4AB 3BEFDB30 0D06092A 864886F7 0D010104
05000381 8100A2EA 9B7BB98D 5C34BAFC D9A0E5AD 445F92A6 EC91F7A4 837F1BF4
43AD0E46 75247098 78B39916 AA97B68E CFD57C01 AC1008E1 ACBB487E BF364CF7
32ABB519 45E310A7 0BAFB352 5AA3EB2C 5AB47E25 19CFEAFE E9E2FF58 67FF4384
1AFD6924 8998D952 B2ABF958 F0DE70E3 D6594024 E8600186 D2C82361 2A9F6515
833A1A18 12E4
quit
!
!
dot1x system-auth-control
dot1x guest-vlan supplicant
!
!
!
errdisable recovery cause udld
errdisable recovery cause bpduguard
errdisable recovery cause security-violation
errdisable recovery cause channel-misconfig
errdisable recovery cause pagp-flap
errdisable recovery cause dtp-flap
errdisable recovery cause link-flap
errdisable recovery cause sfp-config-mismatch
errdisable recovery cause gbic-invalid
errdisable recovery cause psecure-violation
errdisable recovery cause port-mode-failure
errdisable recovery cause dhcp-rate-limit
errdisable recovery cause mac-limit
errdisable recovery cause vmps
errdisable recovery cause storm-control
errdisable recovery cause inline-power
errdisable recovery cause loopback
errdisable recovery cause small-frame
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
!
interface FastEthernet0/1
description "***May tinh A Longdm***"
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/2
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/3
description "***Lap top cua Tuan Anh***"
switchport mode access
switchport port-security mac-address 0026.9e94.1dfa
spanning-tree portfast
!
interface FastEthernet0/4
description "***Destop cua Tuan ANh***"
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/5
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/6
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/7
description "***Ket noi may tinh cua Cong Anh tren tang 2***"
switchport mode access
switchport port-security mac-address 0019.bb43.f7ba
spanning-tree portfast
!
interface FastEthernet0/8
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/9
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/10
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/11
description ****Connect to Laptop Hoannv****
switchport mode access
switchport port-security
switchport port-security mac-address 7884.3ccd.7cfa
spanning-tree portfast
!
interface FastEthernet0/12
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/13
description ***connect to PC Cuongle****
switchport mode access
switchport port-security maximum 4
switchport port-security
spanning-tree portfast
!
interface FastEthernet0/14
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/15
description ***Connect to PC LoanTTT***
switchport mode access
switchport port-security maximum 4
switchport port-security
spanning-tree portfast
!
interface FastEthernet0/16
description ***Connect to PC HoaNH****
switchport mode access
switchport port-security maximum 4
switchport port-security
spanning-tree portfast
!
interface FastEthernet0/17
description ****Connect to PC AnhNN****
switchport mode access
switchport port-security maximum 10
switchport port-security
spanning-tree portfast
!
interface FastEthernet0/18
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/19
description ****connect to Laptop MAC_ Hungdq ****
switchport mode access
switchport port-security maximum 2
switchport port-security
switchport port-security mac-address 0025.4ba2.b374
switchport port-security mac-address 0800.27e5.f0e7
spanning-tree portfast
!
interface FastEthernet0/20
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/21
description ***connect to PC Hungdq***
switchport mode access
switchport port-security
switchport port-security mac-address 20cf.3064.bc94
spanning-tree portfast
!
interface FastEthernet0/22
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/23
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/24
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/25
description ***Connect to PC Vinhmv****
switchport mode access
switchport port-security mac-address 0024.81ca.b4a3
spanning-tree portfast
!
interface FastEthernet0/26
switchport mode access
dot1x pae authenticator
dot1x port-control auto
dot1x violation-mode protect
dot1x reauthentication
dot1x guest-vlan 41
dot1x auth-fail vlan 1
spanning-tree portfast
!
interface FastEthernet0/27
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/28
switchport access vlan 29
switchport mode access
switchport port-security
switchport port-security aging time 2
switchport port-security violation restrict
switchport port-security aging type inactivity
macro description cisco-desktop
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/29
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/30
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/31
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/32
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/33
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/34
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/35
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/36
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/37
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/38
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/39
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/40
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/41
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/42
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/43
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/44
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/45
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/46
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/47
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/48
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/1
switchport mode trunk
!
interface GigabitEthernet0/2
switchport mode trunk
!
interface Vlan1
ip address 10.4.20.244 255.255.255.0
no ip route-cache
!
ip default-gateway 10.4.20.1
ip http server
ip http authentication local
ip http secure-server
radius-server host 10.4.29.18 auth-port 1812 acct-port 1813 key 123456789
!
control-plane
!
privilege exec level 2 show startup-config
!
line con 0
password 7 104D000A0618
line vty 0 4
exec-timeout 1000 0
password 7 104D000A0618
line vty 5 15
exec-timeout 1000 0
password 7 104D000A0618
!
end
SW-CNTT04#
SW-CNTT04#
-----------------------------------------
Nhưng khi xác thực trên client toàn báo lỗi "Authentication fail"
Client XP-----SW 2960------IAS
Hiện tại là xác thực từ SW với IAS thì OK rồi ví dụ phía dưới:
--------------------
SW-CNTT04#test aaa group radius test1 123456a@ legacy
Attempting authentication test to server-group radius using radius
User was successfully authenticated.
SW-CNTT04#
015057: *Apr 24 18:10:54.376: AAA: parse name=<no string> idb type=-1 tty=-1
015058: *Apr 24 18:10:54.376: AAA/MEMORY: create_user (0x2BC897C) user='test1' ruser='NULL' ds0=0 port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)
015059: *Apr 24 18:10:54.376: RADIUS: Pick NAS IP for u=0x2BC897C tableid=0 cfg_addr=0.0.0.0
015060: *Apr 24 18:10:54.376: RADIUS: ustruct sharecount=1
015061: *Apr 24 18:10:54.376: Radius: radius_port_info() success=0 radius_nas_port=1
015062: *Apr 24 18:10:54.376: RADIUS/ENCODE: Best Local IP-Address 10.4.20.244 for Radius-Server 10.4.29.18
015063: *Apr 24 18:10:54.376: RADIUS(00000000): Send Access-Request to 10.4.29.18:1812 id 1645/71, len 57
015064: *Apr 24 18:10:54.376: RADIUS: authenticator F9 E5 1A 6C B3 41 6A 0E - EE 03 DF 33 BA 31 45 94
015065: *Apr 24 18:10:54.376: RADIUS: NAS-IP-Address [4] 6 10.4.20.244
015066: *Apr 24 18:10:54.384: RADIUS: NAS-Port-Type [61] 6 Async [0]
015067: *Apr 24 18:10:54.384: RADIUS: User-Name [1] 7 "test1"
015068: *Apr 24 18:10:54.384: RADIUS: User-Password [2] 18 *
015069: *Apr 24 18:10:54.384: RADIUS: Received from id 1645/71 10.4.29.18:1812, Access-Accept, len 74
015070: *Apr 24 18:10:54.384: RADIUS: authenticator D4 EF 15 40 36 AB 69 A2 - FC F8 0F 7B 24 14 4B D0
015071: *Apr 24 18:10:54.384: RADIUS: Service-Type [6] 6 Framed [2]
015072: *Apr 24 18:10:54.384: RADIUS: Tunnel-Medium-Type [65] 6 00:ALL_802 [6]
015073: *Apr 24 18:10:54.384: RADIUS: Tunnel-Private-Group[81] 4 "29"
015074: *Apr 24 18:10:54.384: RADIUS: Tunnel-Type [64] 6 00:VLAN [13]
015075: *Apr 24 18:10:54.384: RADIUS: Class [25] 32
015076: *Apr 24 18:10:54.384: RADIUS: 2B 43 03 59 00 00 01 37 00 01 0A 04 1D 12 01 C6 0F 77 08 A7 49 86 00 00 00 00 00 00 00 17 [ +CY7wI]
015077: *Apr 24 18:10:54.384: RADIUS: saved authorization data for user 2BC897C at 1F91900
015078: *Apr 24 18:10:54.384: AAA/MEMORY: free_user (0x2BC897C) user='test1' ruser='NULL' port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 vrf= (id=0)
--------------------------------
Cấu hình SW của em đây ạ:
SW-CNTT04#show run
Building configuration...
Current configuration : 10063 bytes
!
version 12.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
service sequence-numbers
!
hostname SW-CNTT04
!
boot-start-marker
boot-end-marker
!
enable password 7 02150C5903094C010D4F0D140C19
!
username anhnc privilege 2 password 7 104D000A0618
username shb-admin privilege 15 password 7 14041A09040B690B652937382B1D
username cisco privilege 2 password 7 030752180500
aaa new-model
!
!
aaa authentication login default local
aaa authentication dot1x default group radius
aaa authorization exec default local
aaa authorization network default group radius
!
!
!
aaa session-id common
system mtu routing 1500
ip subnet-zero
!
!
!
crypto pki trustpoint TP-self-signed-4276715776
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-4276715776
revocation-check none
rsakeypair TP-self-signed-4276715776
!
!
crypto pki certificate chain TP-self-signed-4276715776
certificate self-signed 01
30820242 308201AB A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 34323736 37313537 3736301E 170D3933 30333031 30303030
35335A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D34 32373637
31353737 3630819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100C42F D1F3682C 7649FDD8 30364D6F B5AB4B82 80E9CFC1 75195E23 FC2F72F4
F1386C3C 63107A63 F97ECAE4 A37EFA53 050D9076 2EEB6660 0190A028 616A8E82
CB8DE052 429A943E 6ACF87F0 CD42ADCE 324BFAF8 953ED848 81392727 8FB03F00
43A7B0D1 B45105AD C0EDD026 64EE6769 12A445B9 DDCCA505 0D32DE9B F4F4F81D
3D0B0203 010001A3 6A306830 0F060355 1D130101 FF040530 030101FF 30150603
551D1104 0E300C82 0A53572D 434E5454 30342E30 1F060355 1D230418 30168014
A7828EC1 8213C249 919F6C41 AFBDF9F4 AB3BEFDB 301D0603 551D0E04 160414A7
828EC182 13C24991 9F6C41AF BDF9F4AB 3BEFDB30 0D06092A 864886F7 0D010104
05000381 8100A2EA 9B7BB98D 5C34BAFC D9A0E5AD 445F92A6 EC91F7A4 837F1BF4
43AD0E46 75247098 78B39916 AA97B68E CFD57C01 AC1008E1 ACBB487E BF364CF7
32ABB519 45E310A7 0BAFB352 5AA3EB2C 5AB47E25 19CFEAFE E9E2FF58 67FF4384
1AFD6924 8998D952 B2ABF958 F0DE70E3 D6594024 E8600186 D2C82361 2A9F6515
833A1A18 12E4
quit
!
!
dot1x system-auth-control
dot1x guest-vlan supplicant
!
!
!
errdisable recovery cause udld
errdisable recovery cause bpduguard
errdisable recovery cause security-violation
errdisable recovery cause channel-misconfig
errdisable recovery cause pagp-flap
errdisable recovery cause dtp-flap
errdisable recovery cause link-flap
errdisable recovery cause sfp-config-mismatch
errdisable recovery cause gbic-invalid
errdisable recovery cause psecure-violation
errdisable recovery cause port-mode-failure
errdisable recovery cause dhcp-rate-limit
errdisable recovery cause mac-limit
errdisable recovery cause vmps
errdisable recovery cause storm-control
errdisable recovery cause inline-power
errdisable recovery cause loopback
errdisable recovery cause small-frame
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
!
interface FastEthernet0/1
description "***May tinh A Longdm***"
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/2
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/3
description "***Lap top cua Tuan Anh***"
switchport mode access
switchport port-security mac-address 0026.9e94.1dfa
spanning-tree portfast
!
interface FastEthernet0/4
description "***Destop cua Tuan ANh***"
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/5
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/6
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/7
description "***Ket noi may tinh cua Cong Anh tren tang 2***"
switchport mode access
switchport port-security mac-address 0019.bb43.f7ba
spanning-tree portfast
!
interface FastEthernet0/8
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/9
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/10
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/11
description ****Connect to Laptop Hoannv****
switchport mode access
switchport port-security
switchport port-security mac-address 7884.3ccd.7cfa
spanning-tree portfast
!
interface FastEthernet0/12
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/13
description ***connect to PC Cuongle****
switchport mode access
switchport port-security maximum 4
switchport port-security
spanning-tree portfast
!
interface FastEthernet0/14
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/15
description ***Connect to PC LoanTTT***
switchport mode access
switchport port-security maximum 4
switchport port-security
spanning-tree portfast
!
interface FastEthernet0/16
description ***Connect to PC HoaNH****
switchport mode access
switchport port-security maximum 4
switchport port-security
spanning-tree portfast
!
interface FastEthernet0/17
description ****Connect to PC AnhNN****
switchport mode access
switchport port-security maximum 10
switchport port-security
spanning-tree portfast
!
interface FastEthernet0/18
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/19
description ****connect to Laptop MAC_ Hungdq ****
switchport mode access
switchport port-security maximum 2
switchport port-security
switchport port-security mac-address 0025.4ba2.b374
switchport port-security mac-address 0800.27e5.f0e7
spanning-tree portfast
!
interface FastEthernet0/20
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/21
description ***connect to PC Hungdq***
switchport mode access
switchport port-security
switchport port-security mac-address 20cf.3064.bc94
spanning-tree portfast
!
interface FastEthernet0/22
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/23
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/24
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/25
description ***Connect to PC Vinhmv****
switchport mode access
switchport port-security mac-address 0024.81ca.b4a3
spanning-tree portfast
!
interface FastEthernet0/26
switchport mode access
dot1x pae authenticator
dot1x port-control auto
dot1x violation-mode protect
dot1x reauthentication
dot1x guest-vlan 41
dot1x auth-fail vlan 1
spanning-tree portfast
!
interface FastEthernet0/27
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/28
switchport access vlan 29
switchport mode access
switchport port-security
switchport port-security aging time 2
switchport port-security violation restrict
switchport port-security aging type inactivity
macro description cisco-desktop
spanning-tree portfast
spanning-tree bpduguard enable
!
interface FastEthernet0/29
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/30
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/31
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/32
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/33
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/34
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/35
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/36
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/37
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/38
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/39
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/40
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/41
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/42
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/43
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/44
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/45
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/46
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/47
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface FastEthernet0/48
switchport access vlan 29
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/1
switchport mode trunk
!
interface GigabitEthernet0/2
switchport mode trunk
!
interface Vlan1
ip address 10.4.20.244 255.255.255.0
no ip route-cache
!
ip default-gateway 10.4.20.1
ip http server
ip http authentication local
ip http secure-server
radius-server host 10.4.29.18 auth-port 1812 acct-port 1813 key 123456789
!
control-plane
!
privilege exec level 2 show startup-config
!
line con 0
password 7 104D000A0618
line vty 0 4
exec-timeout 1000 0
password 7 104D000A0618
line vty 5 15
exec-timeout 1000 0
password 7 104D000A0618
!
end
SW-CNTT04#
SW-CNTT04#
-----------------------------------------
Nhưng khi xác thực trên client toàn báo lỗi "Authentication fail"
Comment