Specifications

AAA Tools for Network Users
17-10 Configuring AAA for Network Users
3. ToenablePEAPoffloadpluslocalauthenticationforallusersofSSIDmycorpat
@example.com,theadministratorentersthefollowingcommand.
RBT-8100# set authentication dot1x ssid mycorp *@example.com peap-mschapv2 server-group-
1 local
Figure 172showstheresultsofthiscombinationofmethods.
Figure 17-2 Remote Pass-Through or Local Authentication
Authenticationproceedsasfollows:
1. WhenuserJose@example.comattemptsauthentication,theRoamAboutswitchsendsan
authenticationrequesttothefirstAAAmethod,whichisservergroup1.
Becauseservergroup1containstwoservers,thefirstRADIUSserver,server1,iscontacted.If
thisserverresponds,theauthenticationproceedsusingserver1.
2. Ifserver1failstorespond,theRoamAboutswitchretriestheauthenticationusingserver2.If
server2responds,theauthenticationproceedsusingserver2.
3. Ifserver2doesnotrespond,becausetheRoamAboutswitchhasnomoreserverstotryin
servergroup1,theRoamAboutswitchattemptsto
authenticateusingthenextAAAmethod,
whichisthelocalmethod.
4. TheRoamAboutswitchconsultsitsloca ldatabaseforanentrythatmatches
Jose@example.com.
5. Ifasuitablelocaldatabaseentryexists,theauthenticationproceeds.Ifnot,authenticationfails
andJose@example.comisnotallowedtoaccessthe network.
RADIUS
Server-1
Server-group-1
RADIUS
Server-2
RoamAbout
switch
local database
pass fail
set authentication dot1x ssid mycorp *@example.com peap-mschapv2 server-group-1 local
1
1 2 3
4
5