Specifications

Configuring 802.1X Authentication
RoamAbout Mobility System Software Configuration Guide 17-13
Wiredusersarenotelig iblefortheencryptionperformedonthetrafficofwirelessusers,butthey
canbeauthenticatedbyanEAP m ethod,aMACaddress,aWebloginpageservedbythe
RoamAboutswitch,oralastresortusernam e.
Configuring 802.1X Authentication
TheIEEE802.1XstandardisaframeworkforpassingEAPprotocolsoverawiredorwireless
LAN.Withinthisframework,youcanuseTLS,PEAPTTLS,orEAPMD5.MostEAPprotocols
canbepassedthroughtheRoamAboutswitchtotheRADIUSserver.Someprotocolscanbe
processedlocallyonthe
RoamAboutswitch.
Thefollowing802.1Xauthenticationcommandallowsdifferingauthenticationtreatmentsfor
multipleusers:
set authentication dot1x {ssid ssid-name | wired} user-glob [bonded] protocol
method1 [method2] [method3] [method4]
Example
ThefollowingcommandauthenticateswirelessuserTamara,whenrequestingSSIDwetlands,asan
802.1XuserusingthePEAPMSCHAPV2methodviatheservergroupshor ebirds,whichcontains
oneormoreRADIUSservers:
RBT-8100# set authentication dot1x ssid wetlands Tamara peap-mschapv2 shorebirds
Whenauserattemptstoconnectthrough802.1X,thefollowingeventsoccur:
1. Foreach802.1Xloginattempt,MSSexamineseachcommandintheconfigurationfileinstrict
configurationorder.
2. ThefirstcommandwhoseSSIDanduserglobmatchestheSSIDandincomingusernameis
usedtoprocessthisauthentication.Thecommanddetermines
exactlyhowthisparticular
loginattemptisprocessedbytheRoamAboutswitch.
(Formoreinformationaboutuserglobs,seeUserGlobsonpage 14.)