CCNP Switching - AAAdot1x Lab With Explanation - Sysnet Notes
CCNP Switching - AAAdot1x Lab With Explanation - Sysnet Notes
switching : AAAdot1x Lab with explanation ~ Sysnet Notes
SYSNET NOTES
MicroSoft | Cisco | PaloAlto| Networking Notes| Tips | Troubleshooting
Search
Home Cisco> Routing > Switching > PaloAlto Security Cmd Prompt More>
AAA is used in a scenario where a user has to authenticate before getting access to
the network.
Before authentication user wont even get an IP address. The only thing the user is
allowed to do is send his/her credentials which will be forwarded to the AAA server.
If user credentials are OK the port will be unblocked and user will be granted access
to the network.
http://sysnetnotes.blogspot.com/2013/08/ccnpswitchingaaadot1xlab.html 1/8
11/16/2016 CCNP switching : AAAdot1x Lab with explanation ~ Sysnet Notes
The Radius server and application servers will be installed at a future date. You have
been tasked with implementing the above access control as a pre-condition to
installing the servers.
You must use the available IOS switch features.
Solution
http://sysnetnotes.blogspot.com/2013/08/ccnpswitchingaaadot1xlab.html 2/8
11/16/2016 CCNP switching : AAAdot1x Lab with explanation ~ Sysnet Notes
This scenario in particular mentions that there is a new VLAN 40 added to the
network, however, it does not tell you to configure anything using VLAN 40 so you
can ignore it.
Only ports on VLAN 20 are required to be secured using dot1x authentication and
the only port configured on VLAN 20 is fa0/1 (this is why ports Fa0/2 and Fa0/3 are
not configured with authentication).
1. ASW1(config)#aaa new-model
2. ASW1(config)#radius-server host 172.120.39.46 key rad123
3. ASW1(config)#aaa authentication dot1x default group
radius
4. ASW1(config)#dot1x system-auth-control
Explanation
http://sysnetnotes.blogspot.com/2013/08/ccnpswitchingaaadot1xlab.html 3/8
11/16/2016 CCNP switching : AAAdot1x Lab with explanation ~ Sysnet Notes
On the interface level we need to use the "dot1x port-control auto" command.In
auto mode no client connected to that port will be allowed to pass user traffic until
the port has been authorized by the authorization server.
NOTE :Verify configuration using "Show run" command and save the configuration
using "copy run start"
1. Create Access-List
2. Create Access MAP
3. Applying to a VLAN
1. DSW1#conf terminal
2. DSW1(config)#ip access-list standard 10
3. DSW1(config-std-nacl)#permit 172.120.40.0 0.0.0.255
4. DSW1(config-std-nacl)#exit
Click here to View and Download complete CCNA + CCNP PDF Notes
http://sysnetnotes.blogspot.com/2013/08/ccnpswitchingaaadot1xlab.html 4/8
11/16/2016 CCNP switching : AAAdot1x Lab with explanation ~ Sysnet Notes
7. DSW1(config-access-map)# exit
Explanation
Apply on VLAN
NOTE : Applies the VLAN access-map named “MYMAP” to vlan 20 DSW1.Verify and
save the configuration
Related articles
8 Comments:
Rahul
August 12, 2013 at 12:22 AM
REPLY
Patrick Denis
June 10, 2014 at 10:59 AM
thank you !
REPLY
Ken
June 22, 2014 at 9:43 PM
thx bro
REPLY
Paras DESAI
June 24, 2014 at 1:32 AM
Nate Hedstrom
July 2, 2015 at 12:28 AM
It applies the access map to the vlan (in this case traffic on vlan 20 will be applied
against the access map - via entries from the access-list)
REPLY
Unknown
May 31, 2016 at 11:50 PM
Anonymous
August 17, 2016 at 12:14 AM
Luis
August 22, 2016 at 10:55 PM
Thanks a lot!
http://sysnetnotes.blogspot.com/2013/08/ccnpswitchingaaadot1xlab.html 6/8
11/16/2016 CCNP switching : AAAdot1x Lab with explanation ~ Sysnet Notes
REPLY
Enter your comment...
Comment as: Select profile...
Publish
Preview
Links To This Post
Create a Link
Email address... Submit
Sysnetnotes
448 likes
Click here to View and Download complete CCNA + CCNP PDF Notes
CCNA PDF notes and
Interview questions
for 7$
T O TA L PA G E V I E W S
LABELS 2,074,629
AAA Access list Active
directory ARP ASA basic
Basics Batch file BGP
CCNA CCNP
Routing CCNP
Switching cisco
Cisco ISE cmd prompt
http://sysnetnotes.blogspot.com/2013/08/ccnpswitchingaaadot1xlab.html 7/8
11/16/2016 CCNP switching : AAAdot1x Lab with explanation ~ Sysnet Notes
Live Traffic Feed Commands
A visitor from Imus, Cavite Configuration DHCP
viewed "CCNP switching : EIGRP error
AAAdot1x Lab with Etherchannel FAQ
explanation ~ Sysnet Notes" 1
A visitor from Egypt viewed Firewall FortiGate GPO
min ago
"Basic CCNA Interview HSRP internet explorer
Questions AND Answers ~ Interview IPv6 Kali
Sysnet Notes" 2 mins ago
A visitor from Brazil viewed
kaspersky LAB linux
Lockout lotus notes
"How to ping multiple ip magicjack MCP MPLS MST
addresses from cmd prompt ~network monitoring
Sysnet Notes" 3 mins ago
A visitor from Cambodia OSPF paloalto Private
viewed "EIGRP Authentication VLAN Routing Security
~ Sysnet Notes" 9 mins ago short notes software
A visitor from Jakarta, JakartaSPAN Static routing STP
Raya viewed "Basic CCNA
Interview Questions AND
Switching tips
Troubleshooting
Answers ~ Sysnet Notes" 10
A visitor from United Kingdom
mins ago Trustsec VLAN VMware
viewed "CCNP Switching ~ VPN VTP windows
Sysnet Notes" 12 mins ago wireless
A visitor from United Kingdom
viewed "Basic CCNA Interview
Questions AND Answers ~
Sysnet Notes" 13 mins ago
A visitor from Egypt viewed
"EIGRP Notes with Interview
Questions ~ Sysnet Notes" 15
mins ago
A visitor from India viewed
"Basic CCNA Interview
Questions AND Answers ~
Sysnet Notes" 16 mins ago
A visitor from India viewed
"Home ~ Sysnet Notes" 16 mins
ago
Realtime view · Get Feedjit
Click here to View and Download complete CCNA + CCNP PDF Notes
http://sysnetnotes.blogspot.com/2013/08/ccnpswitchingaaadot1xlab.html 8/8