User`s manual

313
DWS-1008 User’s Manual
D-Link Systems, Inc.
Conguring AAA for Network Users
To display the name of each Mobility Prole and its ports, type the following command:
DWS-1008# show mobility-prole
Mobility Profiles
Name Ports
=========================
roses-profile
AP 2
AP 3
AP 4
AP 7
AP 9
To remove a Mobility Prole, type the following command:
clear mobility-prole name
Network User Conguration Scenarios
The following scenarios provide examples of ways in which you use AAA commands to
congure access for users:
General Use of Network User Commands
Enabling RADIUS Pass-Through Authentication
Enabling PEAP-MS-CHAP-V2 Authentication
Enabling PEAP-MS-CHAP-V2 Ofoad
Combining EAP Ofoad with Pass-Through Authentication
Overriding AAA-Assigned VLANs
General Use of Network User Commands
The following example illustrates how to congure IEEE 802.1X network users for
authentication, accounting, ACL ltering, and Mobility Prole assignment:
1. Congure all 802.1X users of SSID mycorp at EXAMPLE to be authenticated by
server group shorebirds. Type the following command:
DWS-1008# set authentication dot1x ssid mycorp EXAMPLE\* pass-through
shorebirds
2. Congure stop-only accounting for all mycorp users at EXAMPLE, for accounting
records to be stored locally. Type the following command:
DWS-1008# set accounting dot1x ssid mycorp EXAMPLE\* stop-only local
success: change accepted.
3. Congure an ACL to lter the inbound packets for each user at EXAMPLE. Type the
following command for each user:
DWS-1008# set user EXAMPLE\username attr lter-id acl-101.in