Specifications

Authentication Configuration Example
April 15, 2011 Page 32 of 36
Configuring the Engineering Group 802.1x End-User Stations
Therearethreeaspectstoconfiguring802.1xfortheengineeringgroup:
ConfigureEAPoneachenduserstation.
•SetupanaccountinRADIUSontheauthenticationserverforeachenduserstation.
Configure802.1xontheswitch.
ConfiguringEAPontheenduserstationandsettinguptheRADIUSaccountforeach
stationis
dependentuponyouroperatingsystemandtheRADIUSapplicationbeingused,respectively.The
importantthingthenetworkadministratorshouldkeepinmindisthatthesetwoconfigurations
shouldbeinplacebeforemovingontothe802.1xconfigurationontheswitch.Inan802.1x
configuration,policyisspecified
intheRADIUSaccountconfigurationontheauthentication
serverusingtheRADIUSFilterID.SeeTheRADIUSFilterIDonpage 9forRADIUSFilterID
information.IfaRADIUSFilterIDexistsfortheuseraccount,theRADIUSprotocolreturnsitin
theRADIUSAcceptmessageandthefirmwareapplies
thepolicytotheuser.
ThefollowingCLIinput:
•EnablesEAPonthestackablefixedswitch
C3(rw)->set eapol enable
•Enables802.1xontheswitch
•Setsportcontroltoforcedauthforallconnectionsbetweenswitchesandrouters,because
theydonotuseauthenticationandwouldbeblockedifnotsettoforcedauth.
System(rw)->set dot1x enable
System(rw)->set dot1x auth-config authcontrolled-portcontrol forced-auth ge.1.5
System(rw)->set dot1x auth-config authcontrolled-portcontrol forced-auth
ge.1.19
System(rw)->set dot1x auth-config authcontrolled-portcontrol forced-auth
ge.2.24
Thiscompletesthe802.1xenduserstationsconfiguration.
Configuring the Engineering Group Siemens CEP Devices
IfaSiemensphoneisinsertedintoaportenabledforSiemensCEP,thefirmwaredetects
communicationonUDP/TCPport4060.UsepolicymanagertoconfigureapolicywithaVLAN,
CoS,andratelimitappropriatetoVoIP .SeetheQoSFeatureGuideConfigurationExamplesection
at:https://extranet.enterasys.com/downloadsforaQoS
VoIPpolicyconfigurationexample.Once
anexistingpolicyisconfigured,thesetceppolicycommandcanbeusedtoapplythepolicy.
Note: Globally enabling 802.1x on a switch sets the port-control type to auto for all ports. Be sure to
set port-control to forced-auth on all ports that will not be authenticating using 802.1x and no other
authentication method is configured. Otherwise these ports will fail authentication and traffic will be
blocked.
Note: CEP is supported on the modular switch platforms. Stackable fixed switch platforms
authenticate IP phone devices using either 802.1x or MAC authentication. 802.1x is used in this
stackable fixed switch authentication example for the IP phone implementation.