Specifications
Configuring 802.1X Authentication
RoamAbout Mobility System Software Configuration Guide 17-13
Wiredusersarenotelig iblefortheencryptionperformedonthetrafficofwirelessusers,butthey
canbeauthenticatedbyanEAP m ethod,aMACaddress,aWebloginpageservedbythe
RoamAboutswitch,oralast‐resortusernam e.
Configuring 802.1X Authentication
TheIEEE802.1XstandardisaframeworkforpassingEAPprotocolsoverawiredorwireless
LAN.Withinthisframework,youcanuseTLS,PEAP‐TTLS,orEAP‐MD5.MostEAPprotocols
canbepassedthroughtheRoamAboutswitchtotheRADIUSserver.Someprotocolscanbe
processedlocallyonthe
RoamAboutswitch.
Thefollowing802.1Xauthenticationcommandallowsdifferingauthenticationtreatmentsfor
multipleusers:
set authentication dot1x {ssid ssid-name | wired} user-glob [bonded] protocol
method1 [method2] [method3] [method4]
Example
ThefollowingcommandauthenticateswirelessuserTamara,whenrequestingSSIDwetlands,asan
802.1XuserusingthePEAP‐MS‐CHAP‐V2methodviatheservergroupshor ebirds,whichcontains
oneormoreRADIUSservers:
RBT-8100# set authentication dot1x ssid wetlands Tamara peap-mschapv2 shorebirds
Whenauserattemptstoconnectthrough802.1X,thefollowingeventsoccur:
1. Foreach802.1Xloginattempt,MSSexamineseachcommandintheconfigurationfileinstrict
configurationorder.
2. ThefirstcommandwhoseSSIDanduserglobmatchestheSSIDandincomingusernameis
usedtoprocessthisauthentication.Thecommanddetermines
exactlyhowthisparticular
loginattemptisprocessedbytheRoamAboutswitch.
(Formoreinformationaboutuserglobs,see“UserGlobs”onpage 1‐4.)