802.1X authentication and MAC authentication enabled with interim accounting and CoA
This use case shows the configuration required on a RUCKUS ICX device to authenticate a non-802.1X-capable client by way of MAC authentication when the client does not respond to 802.1X authentication. In the following example, the switch will attempt 802.1X authentication first. After the 802.1X timeout, the switch will authenticate the printer through MAC authentication.
Create a device profile for the printer's MAC address on the RADIUS server, and configure the attributes in the following table.
RADIUS attributes for the printer profile
| Attribute | Value |
|---|---|
| Tunnel-Medium-Type | 802 |
| Tunnel-Pvt-Group-ID | 200 |
| Tunnel-Type | VLAN |
| Acct-Interim-Interval | 60 |
RUCKUS ICX switch configuration
- Specify RADIUS as an authentication server. The following command configures the switch
to use the configured RADIUS server to authenticate 802.1X authentication or MAC authentication
clients.
device(config)# aaa authentication dot1x default radius
- Configure a RADIUS server. In the following example, the RADIUS server IP address
is 10.20.64.208 and the shared key is "secret". The shared key must match the key
given during client configuration on the RADIUS server. UDP port 1812 is used for
RADIUS authentication messages, and UDP port 1813 is used for RADIUS accounting messages.
device(config)# radius-server host 10.20.64.208 auth-port 1812 acct-port 1813 default key secret dot1x mac-auth web-auth
- Configure the RADIUS accounting and interim accounting so that interim accounting
updates are sent to the RADIUS server. Additionally, enable CoA for dynamic authorization
changes.
device(config)# aaa accounting dot1x default start-stop radius device(config)# aaa accounting mac-auth default start-stop radius device(config)# aaa authorization coa enable device(config)# radius-server accounting interim-updates
- Create a VLAN to be used as the auth-default VLAN. This VLAN must be configured to
enable authentication. When any port is enabled for 802.1X authentication or MAC authentication,
the port is moved into this VLAN by default as a MAC VLAN member. Sometimes the RADIUS
server may authenticate the client but not return VLAN information on where the client
should be placed. The auth-default VLAN is used in this scenario.
device(config)# vlan 2 name auth-default-vlan device(config-vlan-2)# exit
- Create the VLANs that will be assigned to clients by RADIUS. RADIUS will return VLAN
200 for the printer. This VLAN must be active in the
RUCKUS ICX device. A VLAN is active when it has at least one untagged or tagged member port.
In the following example, VLAN 200 is made active by adding the unused port 2/1/12
as an untagged member.
device(config)# vlan 200 name clientA device(config-vlan-200)# untagged ethernet 2/1/12 device(config-vlan-200)# exit
- Specify which VLAN ID to use as the auth-default VLAN under authentication mode. Refer
to step 4 for the use of the auth-default VLAN.
device(config)# authentication device(config-authen)# auth-default-vlan 2
- Enable 802.1X on the switch under authentication mode, and enable 802.1X on port 1/1/11.
Configure the port control mode as
auto for the interface in general configuration mode. This mode enables 802.1X authentication
on the interface.
device(config-authen)# dot1x enable device(config-authen)# dot1x enable ethernet 1/1/11 device(config-authen)# exit device(config)# dot1x port-control auto ethernet 1/1/11
- Enable MAC authentication on the switch under authentication mode, and enable MAC
authentication for port 1/1/11.
device(config)# authentication device(config-authen)# mac-auth enable device(config-authen)# mac-auth enable ethernet 1/1/11 device(config-authen)# exit
- To verify the authentication-related configuration on the switch, use the
show run authenticationcommand. Authentication-related configurations are stored under the keyword "authentication".device# show run authentication authentication critical-vlan 601 auth-default-vlan 2 restricted-vlan 401 auth-fail-action restricted-vlan re-authentication dot1x enable dot1x enable ethe 1/1/11 dot1x guest-vlan 501 mac-authentication enable mac-authentication enable ethe 1/1/11 !
