文章分类 | 推荐文章 | 最新文章 | 热点文章 | 最新软件 | 精品软件 | 下载排行 | 推荐下载 | WPS | 杀毒软件
清风网络
首 页 软件下载 网络学院
QQ 电脑入门 游戏 操作系统 图形处理 办公软件 媒体动画 精文荟萃 工具软件 网络编程 程序开发 网络技术 认证考试 网站建设 文章专栏
当前位置:清风网络网络技术Cisco网络如何建立一个 CCIE Home Lab之Part Six
精品推荐
特别推荐
·Cisco管理的35个常见问题及解答
·思科路由过滤命令详细解说
·Cisco PIX防火墙配置指南
·思科Cisco交换机VLAN的配置技巧
·Cisco教程:路由器的配置及测试
·Cisco 路由器配置语句汇总
·CISCO相关技术大集合
·Cisco防火墙选购配置完全指南
热点TOP10
·思科7200系列
·用于Cisco 2600XM/2691/2800/3700/3800的高密度数字话音/传真网络模块
·Cisco ONS 15302
·Cisco MDS 9000系列企业软件包
·集中资源提升利用率--思科搭建澳大利亚迪肯大学存储网络
·思科需求驱动型供应链和物流
·EIGRP与OSPF
·快速配置Cisco PIX Firewall技巧

如何建立一个 CCIE Home Lab之Part Six

日期:2008年3月16日 作者: 查看:[大字体 中字体 小字体]

  
  Switch (edge switch or wireless access point) - controls the physical access to the
  network based on the authentication status of the client. The switch acts as an
  intermediary (proxy) between the client and the authentication server, requesting
  identity information from the client, verifying that information with the authentication
  server, and relaying a response to the client. The switch includes the RADIUS client, which is responsible for encapsulating and decapsulating the Extensible Authentication
  Protocol (EAP) frames and interacting with the authentication server.
  
  When the switch receives EAPOL frames and relays them to the authentication server,
  the Ethernet header is stripped and the remaining EAP frame is re-encapsulated in the
  RADIUS format. The EAP frames are not modified or examined during encapsulation, and the authentication server must support EAP within the native frame format. When the
  switch receives frames from the authentication server, the server's frame header is
  removed, leaving the EAP frame, which is then encapsulated for Ethernet and sent to the
  client.
  
  There are three states a port can be in when using dot1x: force-authorized, force-unauthorized, and auto. If a port is in force-authorized status, then the switch will not
  prompt for authentication, and will allow all communication through this port. In the
  force-unauthorized status, the client doesn抰 even get a chance to authenticate; it is the
  equivalent of shutting the port down. Even if the user is dot1x capable, the switch just
  ignores any attempt to communicate through the switch.
  
  Dot1x is supported on Layer 2 static-access ports and Layer 3 routed ports, but is not
  supported on the following port types: Trunk Port, Dynamic port, Dynamic-access port,
  EtherChannel Port, Secure Port, or SPAN Ports.
  
  Sample configuration:
  Switch# configure terminal
  Switch(config)# aaa new-model

上一页 [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18] [19] [20] [21] [22] [23] [24] [25] [26] [27] [28] [29] [30] [31] [32] [33] [34] [35] [36] [37] [38] [39] [40] [41] [42] [43] [44] [45] [46] [47] [48] [49] [50] [51] 下一页 



上一篇:Cisco 网络故障的基本排除方法

下一篇:如何建立一个 CCIE Home Lab之Part Five
相关文章:
·我发现了qq的一个惊人秘密!
·教您如何使用无线上网全攻略
·申请的国际域名如何指向个人主页的免费空间
·存储规划方案 如何编写存储战略文档
·如何进行局域网设置
·[传奇世界]如何玩转格斗竞技场
·录像带NTSC格式如何转换PAL格式?
相关软件:
·如何开公司
·一个真实的宋美龄
·功能较强的一个FLASH编辑器
·Windows XP Home Edition SP2简体中文版
·自己动手建立企业网站
·如何在 Solaris 安裝 Anonymous FTP Server
·1901年:一个帝国的背影

特别声明:本站除部分特别声明禁止转载的专稿外的其他文章可以自由转载,但请务必注明出处和原始作者。文章版权归文章原始作者所有。对于被本站转载文章的个人和网站,我们表示深深的谢意。如果本站转载的文章有版权问题请联系编辑人员,我们尽快予以更正。
[打印本页] [关闭窗口] 转载请注明来源:http://www.viphot.com
| 帮助(?) | 版权声明 | 友情连接 | 关于我们 | 信息发布
Copyright 2007 www.viphot.com All Rights Reserved. 鄂ICP备05000083号Powered by:viphot