220 CHAPTER 11: 802.1X CONFIGURATION
4 Configure RADIUS scheme.
[4500]radius scheme cams
[4500-radius-cams]primary authentication 10.110.91.146 1812
[4500-radius-cams]key authentication expert
[4500-radius-cams]server-type 3com
[4500-radius-cams]user-name-format without-domain
5 Configuration association between domain and RADIUS.
[4500-radius-cams]quit
[4500]domain cams
[4500-isp-cams]scheme radius-scheme cams
Configuring the FTP/Telnet User Local Authentication
Configuring local authentication for FTP users is similar to that for Telnet users. The
following example is based on Telnet users.
Networking Requirements Configure the router to authenticate the login
Telnet users locally (see
Figure 59).
Networking Diagram
Figure 59 Local Authentication for Telnet Users
Configuration Procedure
1 Method 1: Using Local scheme.
a Apply AAA authentication to Telnet users.
[4500-ui-vty0-4]authentication-mode scheme
b Create a local user telnet.
[4500]local-user telnet
[4500-luser-telnet]service-type telnet
[4500-luser-telnet]password simple 3com
[4500-luser-telnet]attribute idle-cut 300 access-limit 5
[4500]domain system
[4500-isp-system]scheme local
Telnet users use usernames in the “userid@system” format to log onto the
network and are to be authenticated as users of the system domain.
2 Method 2: Using Local RADIUS authentication server.
Local server method is similar to remote RADIUS authentication. But you should
modify the server IP address to 127.0.0.1, authentication password to 3com, the
UDP port number of the authentication server to 1645.
Configuring the Switch
4500
General RADIUS Setup
The Switch 4500 supports multiple RADIUS schemes, which can be assigned to a
domain.
This guide covers the recommended steps to setup the Switch4500 for login.
Internet
telnet user
Internet
Internet
telnet user
Internet