Flexible Authentication Configuration Prerequisites
Before you configure Flexible authentication, you must establish communication between
the devices and the authentication server. The following items cover the configuration
steps that are required before you configure Flexible authentication:
- Configure the ICX device interaction with the authentication server by configuring
an authentication method list for 802.1X and specifying RADIUS as an authentication
method. The method list takes care of 802.1X authentication and MAC authentication.
For more information, refer to
AAA operations for RADIUS.
device(config)# aaa authentication dot1x default radius
- Configure the RADIUS server to authenticate access to the
RUCKUS ICX device. For more information, refer to
AAA operations for RADIUS.
device(config)# radius-server host 10.20.64.208 auth-port 1812 acct-port 1813 default key secretkey dot1x mac-auth
- After successful authentication, the client is moved to
the RADIUS-assigned VLAN. Configure a VLAN as the auth-default VLAN to enable
authentication. When any port is enabled for 802.1X authentication or MAC
authentication, the port is moved into this VLAN by default. Specific VLANs (for
example, guest VLAN, restricted VLAN, and critical VLAN) can be configured to
place the clients in various VLANs based on authentication failure and timeout
scenarios.
Note: RUCKUS recommends that you configure VLANs you plan to use before assigning them as auth-default-vlan or a special VLAN (guest VLAN, restricted VLAN, or critical VLAN).
device(config)# vlan 20 name auth-default-vlan
- After a successful authentication, user access can
be limited by ACLs. ACLs must be preconfigured on the ICX device, and the RADIUS
server can return the ACL ID or name. If the ACL matches the ACL configured on
the device, it is applied to the port.
device(config)# ip access-list extended 100 device(config-ext-ipacl-100)# permit ip any any
Note: The source IP must be either the user's IP address or “any” because the RUCKUS ICX device dynamically learns the IP addresses of the clients (source). The destination network is user-configurable.
For more information on ACL configuration, refer to IPv4 ACLs. For more information about dynamic ACL assignment, refer to Dynamic ACLs in authentication.
- If any of the clients need to be statically
authenticated or denied access, the MAC addresses of such clients can be
configured using the
authentication filtercommand in interface configuration sub-mode.device(config-if-e1000-1/1/1)# authentication filter permit/deny xxxx.xxxx.xxxx FFFF.FFFF.FFFF
For additional information, refer to Configuring Flexible Authentication on an Interface and the RUCKUS FastIron Command Reference.