User Tools

Site Tools


technical:8021x

This is an old revision of the document!


<markdown> # 802.1x ## Cisco Server Profile ``` radius server <server> address ipv4 <ip> auth-port 1812 acct-port 1813 key <key> ! aaa server radius dynamic-author client <ip> server-key <key> ! ip radius source-interface <interface> ``` AAA Profile ``` aaa new-model aaa authentication dot1x default group radius aaa accounting dot1x default start-stop group radius aaa accounting update newinfo aaa session-id common ``` ### MAB Interface Configuration ``` interface <interface> dot1x pae authenticator authentication periodic authentication port-control auto mab ``` Global Configuration ``` dot1x system-auth-control ``` ### Dynamic VLAN RADIUS Attributes ``` radius-server attribute 6 on-for-login-auth radius-server attribute 8 include-in-access-req radius-server attribute 25 access-request include ``` ## EAP-TLS ## FreeRADIUS RADIUS Client Configuration Edit /etc/raddb/clients.conf ``` Users Configuration ``` <mac> Cleartext-Password := “<mac>”

                   Tunnel-Type = 13,
                   Tunnel-Medium-Type = 6,
                   Tunnel-Private-Group-Id = 10

``` client <name> {

  ipv4addr = <ip>
  proto = udp
  secret = <key>
  nas_type = cisco

``` ### MAB ### WPA2/3 EAP-TLS

- https://wiki.alpinelinux.org/wiki/FreeRadius_EAP-TLS_configuration

## Linux ### MAB ### EAP-TLS ## OpenVPN RADIUS Plugin ## Go RADIUS

</markdown

technical/8021x.1664195383.txt.gz · Last modified: 2022/09/26 08:29 by jc