Re: 802.1x PROBLEMI
emre aksoy <[email protected]> Thu, 10 Sep 2009 04:53:58 -0700 (PDT)
| Newsgroups | gmane.comp.hardware.cisco.turkish |
|---|---|
| Message-ID | <[email protected]> |
Slm dot.1x tarafında guest vlan tanımla kullanıcı authenticate oluncaya kadar quest vlan de kalsın , burdan sisteme login olsun sonrasında switch tekrar authenticate işlemi yapıp uygun vlan e atacaktır. --- On Thu, 9/10/09, Sunay Musaoglu <[email protected]> wrote: From: Sunay Musaoglu <[email protected]> Subject: [cisco-ttl] 802.1x PROBLEMI To: [email protected] Cc: [email protected] Date: Thursday, September 10, 2009, 11:00 AM Merhaba ; Switch , ias configurasyonları ve topoloji resmi ektedir. Ekteki konfigurasyon ile log off oldugumda portumu kapatmıyor. Fakat client ın ethernet kablosunu cekip tekrar switchporta ( fa 0/5 ) taktıgımda ben log off haldeyken ias ve domain controller (ikisi de aynı makina uzerinde) ile baglantı kuramıyor. Dolayısı ile domaine log on olamıyorum. Bu problemi nasıl asabilirim ? Yardımlarınız icin Tesekkurler. iyi calismalar. ---------- TEST_3560#sh run Building configuration. .. Current configuration : 3125 bytes ! version 12.2 no service pad aaa new-model ! ! aaa authentication dot1x default group radius aaa authorization network default group radius aaa accounting dot1x default start-stop group radius aaa accounting system default start-stop group radius ! ! ! aaa session-id common system mtu routing 1500 ip subnet-zero ip routing ! ! ! ! ! dot1x system-auth- control ! ! ! ! ! spanning-tree mode pvst spanning-tree extend system-id ! vlan internal allocation policy ascending ! ! ! ! interface FastEthernet0/ 1 switchport access vlan 10 switchport mode access spanning-tree portfast ! interface FastEthernet0/ 2 ! interface FastEthernet0/ 3 switchport access vlan 5 switchport mode access FA 0/5 ten IAS a ulasamadýgýmda FA 0/3 ten baglanmak amaclý spanning-tree portfast ! interface FastEthernet0/ 4 ! interface FastEthernet0/ 5 switchport mode access dot1x pae authenticator dot1x port-control auto dot1x violation-mode protect spanning-tree portfast ! ! interface Vlan1 no ip address ! interface Vlan5 ip address 2.2.2.1 255.255.255. 0 ! interface Vlan10 ip address 1.1.1.1 255.255.255. 0 ! interface Vlan20 no ip address ! ip classless ip http server ip http secure-server ! ! radius-server host 1.1.1.3 auth-port 1812 acct-port 1813 timeout 4 radius-server retry method reorder radius-server transaction max-tries 10 radius-server retransmit 10 radius-server timeout 4 radius-server deadtime 2 radius-server key 123456 radius-server vsa send authentication ! TEST_3560#sh vlan VLAN Name Status Ports ---- ------------ --------- --------- -- --------- ------------ --------- --------- - 1 default active Fa0/2, Fa0/4, Fa0/5, Fa0/6 Fa0/7, Fa0/8, Fa0/9, Fa0/10 Fa0/11, Fa0/12, Fa0/13, Fa0/14 Fa0/15, Fa0/16, Fa0/17, Fa0/18 Fa0/19, Fa0/20, Fa0/21, Fa0/22 Fa0/23, Fa0/24, Fa0/25, Fa0/26 Fa0/27, Fa0/28, Fa0/29, Fa0/30 Fa0/31, Fa0/32, Fa0/33, Fa0/34 Fa0/35, Fa0/36, Fa0/37, Fa0/38 Fa0/39, Fa0/40, Fa0/41, Fa0/42 Fa0/43, Fa0/44, Fa0/45, Fa0/46 Fa0/47, Fa0/48, Gi0/1, Gi0/2 Gi0/3, Gi0/4 5 CLIENT_VLAN active Fa0/3 10 RADIUS_VLAN active Fa0/1 1002 fddi-default act/unsup 1003 token-ring-default act/unsup 1004 fddinet-default act/unsup 1005 trnet-default act/unsup VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2 ---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------ 1 enet 100001 1500 - - - - - 0 0 5 enet 100005 1500 - - - - - 0 0 10 enet 100010 1500 - - - - - 0 0 1002 fddi 101002 1500 - - - - - 0 0 1003 tr 101003 1500 - - - - - 0 0 1004 fdnet 101004 1500 - - - ieee - 0 0 1005 trnet 101005 1500 - - - ibm - 0 0 Remote SPAN VLANs ------------ --------- --------- --------- --------- --------- - Primary Secondary Type Ports ------- --------- ------------ ----- ------------ --------- --------- --------- --- [Non-text portions of this message have been removed] [Non-text portions of this message have been removed] ------------------------------------ -- Cisco Teknik Tartisma Listesi (Cisco-ttl) Disclaimer: Some of the individuals posting to this site, including the moderators, work for Cisco Systems, Inc. Opinions expressed here and in any corresponding comments are the personal opinions of the original authors, not those of Cisco. Yahoo! Groups Links <*> To visit your group on the web, go to: http://groups.yahoo.com/group/cisco-ttl/ <*> Your email settings: Individual Email | Traditional <*> To change settings online go to: http://groups.yahoo.com/group/cisco-ttl/join (Yahoo! ID required) <*> To change settings via email: mailto:[email protected] mailto:[email protected] <*> To unsubscribe from this group, send an email to: [email protected] <*> Your use of Yahoo! Groups is subject to: http://docs.yahoo.com/info/terms/