Specifications
AAA Tools for Network Users
17-10 Configuring AAA for Network Users
3. ToenablePEAPoffloadpluslocalauthenticationforallusersofSSIDmycorpat
@example.com,theadministratorentersthefollowingcommand.
RBT-8100# set authentication dot1x ssid mycorp *@example.com peap-mschapv2 server-group-
1 local
Figure 17‐2showstheresultsofthiscombinationofmethods.
Figure 17-2 Remote Pass-Through or Local Authentication
Authenticationproceedsasfollows:
1. WhenuserJose@example.comattemptsauthentication,theRoamAboutswitchsendsan
authenticationrequesttothefirstAAAmethod,whichisserver‐group‐1.
Becauseserver‐group‐1containstwoservers,thefirstRADIUSserver,server‐1,iscontacted.If
thisserverresponds,theauthenticationproceedsusingserver‐1.
2. Ifserver‐1failstorespond,theRoamAboutswitchretriestheauthenticationusingserver‐2.If
server‐2responds,theauthenticationproceedsusingserver‐2.
3. Ifserver‐2doesnotrespond,becausetheRoamAboutswitchhasnomoreserverstotryin
server‐group‐1,theRoamAboutswitchattemptsto
authenticateusingthenextAAAmethod,
whichisthelocalmethod.
4. TheRoamAboutswitchconsultsitsloca ldatabaseforanentrythatmatches
Jose@example.com.
5. Ifasuitablelocaldatabaseentryexists,theauthenticationproceeds.Ifnot,authenticationfails
andJose@example.comisnotallowedtoaccessthe network.
RADIUS
Server-1
Server-group-1
RADIUS
Server-2
RoamAbout
switch
local database
pass fail
set authentication dot1x ssid mycorp *@example.com peap-mschapv2 server-group-1 local
1
1 2 3
4
5