Specifications
Configuring 802.1X Authentication
17-14 Configuring AAA for Network Users
Configuring EAP Offload
YoucanconfiguretheRoamAboutSwitchtooffloadallEAPprocessingfromservergroups.In
thiscase,theRADIUSserverisnotrequiredtocommunicateusingtheEAPprotocols.
ForPEAP‐MS‐CHAP‐V2offload,youdefine acompleteuserprofileinthelocalRoamAbout
Switchdatabaseand onlyausername
andpasswordonaRADIUSserver.
Example
ThefollowingcommandauthenticatesallwirelessuserswhorequestSSIDmarshesat
example.combyoffloadingPEAPprocessingontotheRoamAboutSwitch,whilestillperforming
MS‐CHAP‐V2authenticationviatheservergroupshorebirds:
RBT-8100# set authentication dot1x ssid marshes *@example.com peap-mschapv2
shorebirds
TooffloadbothPEAPandMS‐CHAP‐V2processingontotheRoamAboutswitch,usethe
followingcommand:
RBT-8100# set authentication dot1x ssid marshes *@example.com peap-mschapv2
local
Using Pass-Through
Thepass‐throughmethodcausesEAPauthenticationrequeststobeprocessedentirelybyremote
RADIUSserversinservergroups.
Example
ThefollowingcommandenablesusersatEXAMPLEtobeprocessedviaservergroupshorebirdsor
swampbirds:
RBT-8100# set authentication dot1X ssid marshes EXAMPLE/* pass-through
shorebirds swampbirds
TheservergroupswampbirdsiscontactedonlyifalltheRADIUSserversinshorebirdsdonot
respond.
(Foranexampleoftheuseofpass‐throughserversplusthelocaldatabaseforauthentication,see
“RemoteAuthenticationwithLocalBackup”onpage 17‐9.)
Authenticating via a Local Database
ToconfiguretheRoamAboutswitchtoauthenticateandauthorizeauseragainstthelocal
databaseintheRoamAboutswitch,usethefollowingcommand:
set authentication dot1x {ssid ssid-name | wired} user-glob [bonded] protocol
local
Example
Thefollowingcommandauthenticates80 2.1XuserJoseforwiredauthenticationaccessviathe
localdatabase:
RBT-8100# set authentication dot1X Jose wired peap-mschapv2 local
success: change accepted.