This is an old revision of the document!
<markdown> # 802.1x ## Cisco Server Profile ``` radius server <server> address ipv4 <ip> auth-port 1812 acct-port 1813 key <key> ! aaa server radius dynamic-author client <ip> server-key <key> ! ip radius source-interface <interface> ``` AAA Profile ``` aaa new-model aaa authentication dot1x default group radius aaa accounting dot1x default start-stop group radius aaa accounting update newinfo aaa session-id common ``` ### MAB Interface Configuration ``` interface <interface> dot1x pae authenticator authentication periodic authentication port-control auto mab ``` Global Configuration ``` dot1x system-auth-control ``` ### Dynamic VLAN RADIUS Attributes ``` radius-server attribute 6 on-for-login-auth radius-server attribute 8 include-in-access-req radius-server attribute 25 access-request include ``` ## EAP-TLS ## FreeRADIUS RADIUS Client Configuration Edit /etc/raddb/clients.conf ``` Users Configuration ``` <mac> Cleartext-Password := “<mac>”
Tunnel-Type = 13, Tunnel-Medium-Type = 6, Tunnel-Private-Group-Id = 10
``` client <name> {
ipv4addr = <ip> proto = udp secret = <key> nas_type = cisco
``` ### MAB ### WPA2/3 EAP-TLS
- https://wiki.alpinelinux.org/wiki/FreeRadius_EAP-TLS_configuration
## Linux ### MAB ### EAP-TLS ## OpenVPN RADIUS Plugin ## Go RADIUS
</markdown