αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ 802.1X αž“αŸ…αž›αžΎ Cisco Switchs αžŠαŸ„αž™αž”αŸ’αžšαžΎ Failover NPS (Windows RADIUS with AD)

αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ 802.1X αž“αŸ…αž›αžΎ Cisco Switchs αžŠαŸ„αž™αž”αŸ’αžšαžΎ Failover NPS (Windows RADIUS with AD)
αž…αžΌαžšαž™αžΎαž„αž–αž·αž…αžΆαžšαžŽαžΆαž€αŸ’αž“αž»αž„αž€αžΆαžšαž’αž“αž»αžœαžαŸ’αžαž€αžΆαžšαž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ Windows Active Directory + NPS (αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž˜αŸ 2 αžŠαžΎαž˜αŸ’αž”αžΈαž’αžΆαž“αžΆαž€αžΆαžšαž’αžαŸ‹αž±αž“αž€αŸ†αž αž»αžŸ) + αžŸαŸ’αžαž„αŸ‹αžŠαžΆαžš 802.1x αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αžΆαžšαž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαž„αž€αžΆαžšαž…αžΌαž›αž”αŸ’αžšαžΎ αž“αž·αž„αž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ - domain computers - devices. αž’αŸ’αž“αž€β€‹αž’αžΆαž…β€‹αžŸαŸ’αž‚αžΆαž›αŸ‹β€‹αž‘αŸ’αžšαžΉαžŸαŸ’αžŠαžΈβ€‹αž“αŸαŸ‡β€‹αžαžΆαž˜β€‹αžŸαŸ’αžŠαž„αŸ‹αžŠαžΆαžšβ€‹αž“αŸ…β€‹αž›αžΎ Wikipedia αžαžΆαž˜β€‹αžαŸ†αžŽαž—αŸ’αž‡αžΆαž”αŸ‹αŸ– IEEE ៨០្.៑X

αžŠαŸ„αž™αžŸαžΆαžš "αž˜αž“αŸ’αž‘αžΈαžšαž–αž·αžŸαŸ„αž’αž“αŸ" αžšαž”αžŸαŸ‹αžαŸ’αž‰αž»αŸ†αž˜αžΆαž“αž€αž˜αŸ’αžšαž·αžαž€αŸ’αž“αž»αž„αž’αž“αž’αžΆαž“ αžαž½αž“αžΆαž‘αžΈαžšαž”αžŸαŸ‹ NPS αž“αž·αž„αž§αž”αž€αžšαžŽαŸαž”αž‰αŸ’αž‡αžΆαžŠαŸ‚αž“αž‚αžΊαžαŸ’αžšαžΌαžœαž‚αŸ’αž“αžΆ αž”αŸ‰αž»αž“αŸ’αžαŸ‚αžαŸ’αž‰αž»αŸ†αžŸαžΌαž˜αžŽαŸ‚αž“αžΆαŸ†αž±αŸ’αž™αž’αŸ’αž“αž€αž“αŸ…αžαŸ‚αž”αŸ†αž”αŸ‚αž€αžŸαŸαžœαžΆαž€αž˜αŸ’αž˜αžŸαŸ†αžαžΆαž“αŸ‹αŸ—αž”αŸ‚αž”αž“αŸαŸ‡αŸ”

αžαŸ’αž‰αž»αŸ†αž˜αž·αž“αžŠαžΉαž„αžœαž·αž’αžΈαžŸαŸ’αžαž„αŸ‹αžŠαžΆαžšαžŠαžΎαž˜αŸ’αž”αžΈαž’αŸ’αžœαžΎαžŸαž˜αž€αžΆαž›αž€αž˜αŸ’αž˜αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ Windows NPS (αž‚αŸ„αž›αž€αžΆαžšαžŽαŸ) αžŠαžΌαž…αŸ’αž“αŸαŸ‡αž™αžΎαž„αž“αžΉαž„αž”αŸ’αžšαžΎαžŸαŸ’αž‚αŸ’αžšαžΈαž” PowerShell αžŠαŸ‚αž›αžŠαžΆαž€αŸ‹αž±αŸ’αž™αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαžŠαŸ„αž™αž€αž˜αŸ’αž˜αžœαž·αž’αžΈαž€αŸ†αžŽαžαŸ‹αž–αŸαž›αž—αžΆαžšαž€αž·αž…αŸ’αž… (αž’αŸ’αž“αž€αž“αž·αž–αž“αŸ’αž’αž‚αžΊαž‡αžΆαž’αžαžΈαžαžŸαž αž€αžΆαžšαžΈαžšαž”αžŸαŸ‹αžαŸ’αž‰αž»αŸ†)αŸ” αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αž—αžΆαž–αžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœαž“αŸƒαž€αž»αŸ†αž–αŸ’αž™αžΌαž‘αŸαžšαžŠαŸ‚αž“ αž“αž·αž„αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž§αž”αž€αžšαžŽαŸαžŠαŸ‚αž›αž˜αž·αž“αž’αžΆαž… 802.1x (αž‘αžΌαžšαžŸαŸαž–αŸ’αž‘ αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž”αŸ„αŸ‡αž–αž»αž˜αŸ’αž–αŸ”αž›αŸ”) αž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž€αŸ’αžšαž»αž˜αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αž€αŸ†αžŽαžαŸ‹ αž αžΎαž™αž€αŸ’αžšαž»αž˜αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αž„αŸ’αž€αžΎαžαŸ”

αž“αŸ…αž…αž»αž„αž”αž‰αŸ’αž…αž”αŸ‹αž“αŸƒαž’αžαŸ’αžαž”αž‘ αžαŸ’αž‰αž»αŸ†αž“αžΉαž„αž”αŸ’αžšαžΆαž”αŸ‹αž’αŸ’αž“αž€αž’αŸ†αž–αžΈαž—αžΆαž–αžŸαŸ’αž˜αž»αž‚αŸ’αžšαžŸαŸ’αž˜αžΆαž‰αž˜αž½αž™αž…αŸ†αž“αž½αž“αž“αŸƒαž€αžΆαžšαž’αŸ’αžœαžΎαž€αžΆαžšαž‡αžΆαž˜αž½αž™ 802.1x - αžšαž”αŸ€αž”αžŠαŸ‚αž›αž’αŸ’αž“αž€αž’αžΆαž…αž”αŸ’αžšαžΎαž€αž»αž„αžαžΆαž€αŸ‹αžŠαŸ‚αž›αž˜αž·αž“αž’αžΆαž…αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαž„αž”αžΆαž“ αžαžΆαž˜αžœαž“αŸ’αž ACLs αž‡αžΆαžŠαžΎαž˜αŸ” αžαŸ’αž‰αž»αŸ†αž“αžΉαž„αž…αŸ‚αž€αžšαŸ†αž›αŸ‚αž€αž–αŸαžαŸŒαž˜αžΆαž“αž’αŸ†αž–αžΈ "αž—αžΆαž–αž˜αž·αž“αž”αŸ’αžšαž€αŸ’αžšαžαžΈ" αžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž”αžΆαž“αž…αžΆαž”αŸ‹αŸ”. .

αž…αžΌαžšαž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αž‡αžΆαž˜αž½αž™αž“αžΉαž„αž€αžΆαžšαžŠαŸ†αž‘αžΎαž„ αž“αž·αž„αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž€αžΆαžšαž”αžšαžΆαž‡αŸαž™ NPS αž“αŸ…αž›αžΎ Windows Server 2012R2 (αž’αŸ’αžœαžΈαž‚αŸ’αžšαž”αŸ‹αž™αŸ‰αžΆαž„αž‚αžΊαžŠαžΌαž…αž‚αŸ’αž“αžΆαž€αŸ’αž“αž»αž„αž†αŸ’αž“αžΆαŸ† 2016): αžαžΆαž˜αžšαž™αŸˆ Server Manager -> Add Roles and Features Wizard αž‡αŸ’αžšαžΎαžŸαžšαžΎαžŸαžαŸ‚ Network Policy ServerαŸ”

αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ 802.1X αž“αŸ…αž›αžΎ Cisco Switchs αžŠαŸ„αž™αž”αŸ’αžšαžΎ Failover NPS (Windows RADIUS with AD)

αž¬αž”αŸ’αžšαžΎ PowerShellαŸ–

Install-WindowsFeature NPAS -IncludeManagementTools

αž€αžΆαžšαž”αž‰αŸ’αž‡αžΆαž€αŸ‹αžαžΌαž…αž˜αž½αž™ - αž…αžΆαž”αŸ‹αžαžΆαŸ†αž„αž–αžΈαžŸαž˜αŸ’αžšαžΆαž”αŸ‹ αž€αžΆαžšαž–αžΆαžš EAP (PEAP) αž’αŸ’αž“αž€αž”αŸ’αžšαžΆαž€αžŠαž‡αžΆαžαŸ’αžšαžΌαžœαž€αžΆαžšαžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžšαž”αž‰αŸ’αž‡αžΆαž€αŸ‹αž–αžΈαž—αžΆαž–αžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœαž“αŸƒαž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž˜αŸ (αž‡αžΆαž˜αž½αž™αž“αžΉαž„αžŸαž·αž‘αŸ’αž’αž·αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αžŸαž˜αžšαž˜αŸ’αž™) αžŠαŸ‚αž›αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αž‡αžΏαž‘αž»αž€αž…αž·αžαŸ’αžαž›αžΎαž€αž»αŸ†αž–αŸ’αž™αžΌαž‘αŸαžšαž’αžαž·αžαž·αž‡αž“ αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž˜αž€αž’αŸ’αž“αž€αž‘αŸ†αž“αž„αž‡αžΆαžαŸ’αžšαžΌαžœαžŠαŸ†αž‘αžΎαž„αžαž½αž“αžΆαž‘αžΈ αž’αžΆαž‡αŸ’αž‰αžΆαž’αžšαž•αŸ’αžαž›αŸ‹αžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžš. αž”αŸ‰αž»αž“αŸ’αžαŸ‚αž™αžΎαž„αž“αžΉαž„αžŸαž“αŸ’αž˜αžαŸ‹αžαžΆ CA αž’αŸ’αž“αž€αž”αžΆαž“αžŠαŸ†αž‘αžΎαž„αžšαž½αž…αž αžΎαž™...

αž…αžΌαžšαž’αŸ’αžœαžΎαžŠαžΌαž…αž‚αŸ’αž“αžΆαž“αŸ…αž›αžΎαž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž˜αŸαž‘αžΈαž–αžΈαžšαŸ” αžαŸ„αŸ‡αž”αž„αŸ’αž€αžΎαžαžαžαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αžŸαŸ’αž‚αŸ’αžšαžΈαž” C:Scripts αž“αŸ…αž›αžΎ servers αž“αž·αž„ network folder αž“αŸ…αž›αžΎ server αž‘αžΈαž–αžΈαžš SRV2NPS-config $

αžαŸ„αŸ‡αž”αž„αŸ’αž€αžΎαžαžŸαŸ’αž‚αŸ’αžšαžΈαž” PowerShell αž“αŸ…αž›αžΎαž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž˜αŸαžŠαŸ†αž”αžΌαž„ C:ScriptsExport-NPS-config.ps1 αž‡αžΆαž˜αž½αž™αž“αžΉαž„αžαŸ’αž›αžΉαž˜αžŸαžΆαžšαžŠαžΌαž…αžαžΆαž„αž€αŸ’αžšαŸ„αž˜αŸ–

Export-NpsConfiguration -Path "SRV2NPS-config$NPS.xml"

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž“αŸαŸ‡ αž…αžΌαžšαž™αžΎαž„αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž—αžΆαžšαž€αž·αž…αŸ’αž…αž“αŸ…αž€αŸ’αž“αž»αž„ Task ShedulerαŸ– "αž€αžΆαžšαž“αžΆαŸ†αž…αŸαž‰-NpsConfiguration"

powershell -executionpolicy unrestricted -f "C:ScriptsExport-NPS-config.ps1"

αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž‘αžΆαŸ†αž„αž’αžŸαŸ‹ - αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαžŠαŸ„αž™αžŸαž·αž‘αŸ’αž’αž·αžαŸ’αž–αžŸαŸ‹αž”αŸ†αž•αž»αž
αž”αŸ’αžšαž…αžΆαŸ†αžαŸ’αž„αŸƒ - αž’αŸ’αžœαžΎαž€αž·αž…αŸ’αž…αž€αžΆαžšαž˜αŸ’αžαž„αž‘αŸ€αžαžšαŸ€αž„αžšαžΆαž›αŸ‹ 10 αž“αžΆαž‘αžΈαž˜αŸ’αžαž„αŸ” αž€αŸ’αž“αž»αž„αžšαž™αŸˆαž–αŸαž› 8 αž˜αŸ‰αŸ„αž„αŸ”

αž“αŸ…αž›αžΎ NPS αž”αž˜αŸ’αžšαž»αž„αž‘αž»αž€ αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž€αžΆαžšαž“αžΆαŸ†αž…αžΌαž›αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹ (αž‚αŸ„αž›αž€αžΆαžšαžŽαŸ)αŸ–
αžαŸ„αŸ‡αž”αž„αŸ’αž€αžΎαžαžŸαŸ’αž‚αŸ’αžšαžΈαž” PowerShellαŸ–

echo Import-NpsConfiguration -Path "c:NPS-configNPS.xml" >> C:ScriptsImport-NPS-config.ps1

αž“αž·αž„β€‹αž—αžΆαžšαž€αž·αž…αŸ’αž…β€‹αžŠαžΎαž˜αŸ’αž”αžΈβ€‹αž’αž“αž»αžœαžαŸ’αžβ€‹αžœαžΆβ€‹αž‡αžΆβ€‹αžšαŸ€αž„β€‹αžšαžΆαž›αŸ‹ 10 αž“αžΆαž‘αžΈβ€‹:

powershell -executionpolicy unrestricted -f "C:ScriptsImport-NPS-config.ps1"

αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž‘αžΆαŸ†αž„αž’αžŸαŸ‹ - αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαžŠαŸ„αž™αžŸαž·αž‘αŸ’αž’αž·αžαŸ’αž–αžŸαŸ‹αž”αŸ†αž•αž»αž
αž”αŸ’αžšαž…αžΆαŸ†αžαŸ’αž„αŸƒ - αž’αŸ’αžœαžΎαž€αž·αž…αŸ’αž…αž€αžΆαžšαž˜αŸ’αžαž„αž‘αŸ€αžαžšαŸ€αž„αžšαžΆαž›αŸ‹ 10 αž“αžΆαž‘αžΈαž˜αŸ’αžαž„αŸ” αž€αŸ’αž“αž»αž„αžšαž™αŸˆαž–αŸαž› 8 αž˜αŸ‰αŸ„αž„αŸ”

αž₯αž‘αžΌαžœαž“αŸαŸ‡ αžŠαžΎαž˜αŸ’αž”αžΈαž–αž·αž“αž·αžαŸ’αž™αž˜αžΎαž› αžŸαžΌαž˜αž”αž“αŸ’αžαŸ‚αž˜αž‘αŸ… NPS αž“αŸ…αž›αžΎαž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž˜αŸαž˜αž½αž™ (!) αž€αž»αž„αžαžΆαž€αŸ‹αž–αžΈαžšαž”αžΈαž“αŸ…αž€αŸ’αž“αž»αž„αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž—αŸ’αž‰αŸ€αžœ RADIUS (IP αž“αž·αž„ Shared Secret) αž‚αŸ„αž›αž€αžΆαžšαžŽαŸαžŸαŸ’αž“αžΎαžŸαž»αŸ†αž€αžΆαžšαžαž—αŸ’αž‡αžΆαž”αŸ‹αž–αžΈαžšαŸ– WIRED-αž—αŸ’αž‡αžΆαž”αŸ‹ (αž›αž€αŸ’αžαžαžŽαŸ’αžŒαŸ– β€œαž”αŸ’αžšαž—αŸαž‘αž…αŸ’αžšαž€ NAS αž‚αžΊ Ethernet”) αž“αž·αž„ αžœαŸ‰αžΆαž™αž αŸ’αžœαžΆαž™ - αžŸαž αž‚αŸ’αžšαžΆαžŸ (αž›αž€αŸ’αžαžαžŽαŸ’αžŒαŸ– β€œαž”αŸ’αžšαž—αŸαž‘αž…αŸ’αžšαž€ NAS αž‚αžΊ IEEE 802.11”) αž€αŸαžŠαžΌαž…αž‡αžΆαž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž”αžŽαŸ’αžαžΆαž‰ αž…αžΌαž›αž”αŸ’αžšαžΎαž§αž”αž€αžšαžŽαŸαž”αžŽαŸ’αžαžΆαž‰αžŸαŸŠαžΈαžŸαŸ’αž€αžΌ (αž’αŸ’αž“αž€αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαž„αž”αžŽαŸ’αžαžΆαž‰)αŸ–

Условия:
Π“Ρ€ΡƒΠΏΠΏΡ‹ Windows - domainsg-network-admins
ΠžΠ³Ρ€Π°Π½ΠΈΡ‡Π΅Π½ΠΈΡ:
ΠœΠ΅Ρ‚ΠΎΠ΄Ρ‹ ΠΏΡ€ΠΎΠ²Π΅Ρ€ΠΊΠΈ подлинности - ΠŸΡ€ΠΎΠ²Π΅Ρ€ΠΊΠ° ΠΎΡ‚ΠΊΡ€Ρ‹Ρ‚Ρ‹ΠΌ тСкстом (PAP, SPAP)
ΠŸΠ°Ρ€Π°ΠΌΠ΅Ρ‚Ρ€Ρ‹:
Атрибуты RADIUS: Π‘Ρ‚Π°Π½Π΄Π°Ρ€Ρ‚ - Service-Type - Login
ЗависящиС ΠΎΡ‚ поставщика - Cisco-AV-Pair - Cisco - shell:priv-lvl=15

αž“αŸ…αž•αŸ’αž“αŸ‚αž€αž”αŸ’αžαžΌαžš αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžŠαžΌαž…αžαžΆαž„αž€αŸ’αžšαŸ„αž˜αŸ–

aaa new-model
aaa local authentication attempts max-fail 5
!
!
aaa group server radius NPS
 server-private 192.168.38.151 auth-port 1812 acct-port 1813 key %shared_secret%
 server-private 192.168.10.151 auth-port 1812 acct-port 1813 key %shared_secret%
!
aaa authentication login default group NPS local
aaa authentication dot1x default group NPS
aaa authorization console
aaa authorization exec default group NPS local if-authenticated
aaa authorization network default group NPS
!
aaa session-id common
!
identity profile default
!
dot1x system-auth-control
!
!
line vty 0 4
 exec-timeout 5 0
 transport input ssh
 escape-character 99
line vty 5 15
 exec-timeout 5 0
 logging synchronous
 transport input ssh
 escape-character 99

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈ 10 αž“αžΆαž‘αžΈ αžšαžΆαž›αŸ‹αž”αŸ‰αžΆαžšαŸ‰αžΆαž˜αŸ‰αŸ‚αžαŸ’αžš clientspolicy αž‚αž½αžšαžαŸ‚αž›αŸαž…αž‘αžΎαž„αž“αŸ…αž›αžΎ NPS αž”αž˜αŸ’αžšαž»αž„αž‘αž»αž€ αž αžΎαž™αž™αžΎαž„αž“αžΉαž„αž’αžΆαž…αž…αžΌαž›αž‘αŸ…αž€αŸ’αž“αž»αž„αž€αž»αž„αžαžΆαž€αŸ‹αžŠαŸ„αž™αž”αŸ’αžšαžΎαž‚αžŽαž“αžΈ ActiveDirectory αžŠαŸ‚αž›αž‡αžΆαžŸαž˜αžΆαž‡αž·αž€αž“αŸƒαž€αŸ’αžšαž»αž˜ domainsg-network-admins (αžŠαŸ‚αž›αž™αžΎαž„αž”αžΆαž“αž”αž„αŸ’αž€αžΎαžαž‡αžΆαž˜αž»αž“) αŸ”

αž…αžΌαžšαž”αž“αŸ’αžαž‘αŸ…αž€αžΆαžšαžŠαŸ†αž‘αžΎαž„ Active Directory - αž”αž„αŸ’αž€αžΎαžαž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž€αŸ’αžšαž»αž˜ αž“αž·αž„αž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹ αž”αž„αŸ’αž€αžΎαžαž€αŸ’αžšαž»αž˜αž…αžΆαŸ†αž”αžΆαž…αŸ‹αŸ”

αž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž€αŸ’αžšαž»αž˜ αž€αž»αŸ†αž–αŸ’αž™αžΌαž‘αŸαžš-8021x-αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹:

Computer Configuration (Enabled)
   Policies
     Windows Settings
        Security Settings
          System Services
     Wired AutoConfig (Startup Mode: Automatic)
Wired Network (802.3) Policies


NPS-802-1x

Name	NPS-802-1x
Description	802.1x
Global Settings
SETTING	VALUE
Use Windows wired LAN network services for clients	Enabled
Shared user credentials for network authentication	Enabled
Network Profile
Security Settings
Enable use of IEEE 802.1X authentication for network access	Enabled
Enforce use of IEEE 802.1X authentication for network access	Disabled
IEEE 802.1X Settings
Computer Authentication	Computer only
Maximum Authentication Failures	10
Maximum EAPOL-Start Messages Sent	 
Held Period (seconds)	 
Start Period (seconds)	 
Authentication Period (seconds)	 
Network Authentication Method Properties
Authentication method	Protected EAP (PEAP)
Validate server certificate	Enabled
Connect to these servers	 
Do not prompt user to authorize new servers or trusted certification authorities	Disabled
Enable fast reconnect	Enabled
Disconnect if server does not present cryptobinding TLV	Disabled
Enforce network access protection	Disabled
Authentication Method Configuration
Authentication method	Secured password (EAP-MSCHAP v2)
Automatically use my Windows logon name and password(and domain if any)	Enabled

αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ 802.1X αž“αŸ…αž›αžΎ Cisco Switchs αžŠαŸ„αž™αž”αŸ’αžšαžΎ Failover NPS (Windows RADIUS with AD)

αžαŸ„αŸ‡αž”αž„αŸ’αž€αžΎαžαž€αŸ’αžšαž»αž˜αžŸαž“αŸ’αžαž·αžŸαž»αž sg-αž€αž»αŸ†αž–αŸ’αž™αžΌαž‘αŸαžš-8021x-vl100αžŠαŸ‚αž›αž‡αžΆαž€αž“αŸ’αž›αŸ‚αž„αžŠαŸ‚αž›αž™αžΎαž„αž“αžΉαž„αž”αž“αŸ’αžαŸ‚αž˜αž€αž»αŸ†αž–αŸ’αž™αžΌαž‘αŸαžšαžŠαŸ‚αž›αž™αžΎαž„αž…αž„αŸ‹αž…αŸ‚αž€αž…αžΆαž™αž‘αŸ… vlan 100 αž“αž·αž„αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αžαž˜αŸ’αžšαž„αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž€αŸ’αžšαž»αž˜αžŠαŸ‚αž›αž”αžΆαž“αž”αž„αŸ’αž€αžΎαžαž–αžΈαž˜αž»αž“αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αŸ’αžšαž»αž˜αž“αŸαŸ‡αŸ–

αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ 802.1X αž“αŸ…αž›αžΎ Cisco Switchs αžŠαŸ„αž™αž”αŸ’αžšαžΎ Failover NPS (Windows RADIUS with AD)

αž’αŸ’αž“αž€αž’αžΆαž…αž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αžαžΆαž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž”αžΆαž“αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαžŠαŸ„αž™αž‡αŸ„αž‚αž‡αŸαž™αžŠαŸ„αž™αž”αžΎαž€ "αž”αžŽαŸ’αžαžΆαž‰ αž“αž·αž„αž˜αž‡αŸ’αžˆαž˜αžŽαŸ’αžŒαž›αž…αŸ‚αž€αžšαŸ†αž›αŸ‚αž€ (αž”αžŽαŸ’αžαžΆαž‰ αž“αž·αž„αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž’αŸŠαžΈαž“αž’αžΊαžŽαž·αž) - αž€αžΆαžšαž•αŸ’αž›αžΆαžŸαŸ‹αž”αŸ’αžαžΌαžšαž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž’αžΆαžŠαžΆαž”αŸ‹αž’αŸαžš (αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž’αžΆαžŠαžΆαž”αŸ‹αž’αŸαžš) - αž›αž€αŸ’αžαžŽαŸˆαžŸαž˜αŸ’αž”αžαŸ’αžαž·αž’αžΆαžŠαžΆαž”αŸ‹αž’αŸαžš" αžŠαŸ‚αž›αž™αžΎαž„αž’αžΆαž…αžƒαžΎαž‰αž•αŸ’αž‘αžΆαŸ†αž„ "αž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αž—αžΆαž–αžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœ"αŸ–

αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ 802.1X αž“αŸ…αž›αžΎ Cisco Switchs αžŠαŸ„αž™αž”αŸ’αžšαžΎ Failover NPS (Windows RADIUS with AD)

αž“αŸ…αž–αŸαž›αž’αŸ’αž“αž€αž‡αžΏαž‡αžΆαž€αŸ‹αžαžΆαž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž“αŸαŸ‡αžαŸ’αžšαžΌαžœαž”αžΆαž“αž’αž“αž»αžœαžαŸ’αžαžŠαŸ„αž™αž‡αŸ„αž‚αž‡αŸαž™ αž’αŸ’αž“αž€αž’αžΆαž…αž”αž“αŸ’αžαž‘αŸ…αž€αžΆαžšαžšαŸ€αž”αž…αŸ†αž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž”αžŽαŸ’αžαžΆαž‰αž“αŸ…αž›αžΎ NPS αž“αž·αž„αž…αŸ’αžšαž€αž”αŸ’αžαžΌαžšαž€αž˜αŸ’αžšαž·αžαž…αžΌαž›αž”αŸ’αžšαžΎαŸ”

αžαŸ„αŸ‡αž”αž„αŸ’αž€αžΎαžαž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž”αžŽαŸ’αžαžΆαž‰ neag-αž€αž»αŸ†αž–αŸ’αž™αžΌαž‘αŸαžš-8021x-vl100:

Conditions:
  Windows Groups - sg-computers-8021x-vl100
  NAS Port Type - Ethernet
Constraints:
  Authentication Methods - Microsoft: Protected EAP (PEAP) - Unencrypted authentication (PAP, SPAP)
  NAS Port Type - Ethernet
Settings:
  Standard:
   Framed-MTU 1344
   TunnelMediumType 802 (includes all 802 media plus Ethernet canonical format)
   TunnelPrivateGroupId  100
   TunnelType  Virtual LANs (VLAN)

αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ 802.1X αž“αŸ…αž›αžΎ Cisco Switchs αžŠαŸ„αž™αž”αŸ’αžšαžΎ Failover NPS (Windows RADIUS with AD)

αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž’αž˜αŸ’αž˜αžαžΆαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž…αŸ’αžšαž€αž”αŸ’αžŠαžΌαžš (αžŸαžΌαž˜αž…αŸ†αžŽαžΆαŸ†αžαžΆαž”αŸ’αžšαž—αŸαž‘αž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹ "αž–αž αž»αžŠαŸ‚αž“" αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αŸ’αžšαžΎ - αž‘αž·αž“αŸ’αž“αž“αŸαž™ & αžŸαŸ†αž‘αŸαž„ αž αžΎαž™αžœαžΆαž€αŸαž˜αžΆαž“αž›αž‘αŸ’αž’αž—αžΆαž–αž“αŸƒαž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αžŠαŸ„αž™αž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“ mac αž•αž„αžŠαŸ‚αžšαŸ” αž€αŸ’αž“αž»αž„αž’αŸ†αž‘αž»αž„αž–αŸαž› "αž€αžΆαžšαž•αŸ’αž›αžΆαžŸαŸ‹αž”αŸ’αžαžΌαžš" αžœαžΆαžŸαž˜αž αŸαžαž»αž•αž›αž€αŸ’αž“αž»αž„αž€αžΆαžšαž”αŸ’αžšαžΎαž“αŸ…αž€αŸ’αž“αž»αž„ αž”αŸ‰αžΆαžšαŸ‰αžΆαž˜αŸ‰αŸ‚αžαŸ’αžšαŸ–


authentication event fail action authorize vlan 100
authentication event no-response action authorize vlan 100

vlan id αž˜αž·αž“β€‹αž˜αŸ‚αž“β€‹αž‡αžΆ "quarantine" αž‘αŸ αž”αŸ‰αž»αž“αŸ’αžαŸ‚β€‹αž‡αžΆβ€‹αž›αŸαžβ€‹αžŠαžŠαŸ‚αž›β€‹αžŠαŸ‚αž›β€‹αž€αž»αŸ†αž–αŸ’αž™αžΌαž‘αŸαžšβ€‹αžšαž”αžŸαŸ‹β€‹αž’αŸ’αž“αž€β€‹αž”αŸ’αžšαžΎβ€‹αž‚αž½αžšβ€‹αž‘αŸ…β€‹αž€αŸ’αžšαŸ„αž™β€‹αž–αŸαž›β€‹αž…αžΌαž›β€‹αžŠαŸ„αž™β€‹αž‡αŸ„αž‚αž‡αŸαž™ - αžšαž αžΌαžαžŠαž›αŸ‹β€‹αž™αžΎαž„β€‹αž”αŸ’αžšαžΆαž€αžŠβ€‹αžαžΆβ€‹αž’αŸ’αžœαžΈαŸ—β€‹αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšβ€‹αžŠαžΌαž…β€‹αžŠαŸ‚αž›β€‹αžœαžΆβ€‹αž‚αž½αžšαŸ” αž”αŸ‰αžΆαžšαŸ‰αžΆαž˜αŸ‰αŸ‚αžαŸ’αžšαžŠαžΌαž…αž‚αŸ’αž“αžΆαž‘αžΆαŸ†αž„αž“αŸαŸ‡αž’αžΆαž…αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αŸ’αžšαžΎαž“αŸ…αž€αŸ’αž“αž»αž„αžŸαŸαžŽαžΆαžšαžΈαž™αŸ‰αžΌαž•αŸ’αžŸαŸαž„αž‘αŸ€αž αž§αž‘αžΆαž αžšαžŽαŸ αž“αŸ…αž–αŸαž›αžŠαŸ‚αž›αž€αž»αž„αžαžΆαž€αŸ‹αžŠαŸ‚αž›αž˜αž·αž“αž’αžΆαž…αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαž„αž”αžΆαž“αžαŸ’αžšαžΌαžœαž”αžΆαž“αžŠαŸ„αžαž…αžΌαž›αž‘αŸ…αž€αŸ’αž“αž»αž„αž…αŸ’αžšαž€αž“αŸαŸ‡ αž αžΎαž™αž’αŸ’αž“αž€αž…αž„αŸ‹αž±αŸ’αž™αž§αž”αž€αžšαžŽαŸαž‘αžΆαŸ†αž„αž’αžŸαŸ‹αžŠαŸ‚αž›αž”αžΆαž“αž—αŸ’αž‡αžΆαž”αŸ‹αž‘αŸ…αžœαžΆαžŠαŸ‚αž›αž˜αž·αž“αž”αžΆαž“αž†αŸ’αž›αž„αž€αžΆαžαŸ‹αž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αžŠαžΎαž˜αŸ’αž”αžΈαž’αŸ’αž›αžΆαž€αŸ‹αž…αžΌαž›αž‘αŸ…αž€αŸ’αž“αž»αž„ vlan αž‡αžΆαž€αŸ‹αž›αžΆαž€αŸ‹αž˜αž½αž™ ("αž€αžΆαžšαžŠαžΆαž…αŸ‹αž–αžΈαž‚αŸ")αŸ”

αž”αŸ’αžαžΌαžšαž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž…αŸ’αžšαž€αž€αŸ’αž“αž»αž„ 802.1x host-mode multi-domain mode

default int range Gi1/0/39-41
int range Gi1/0/39-41
shu
des PC-IPhone_802.1x
switchport mode access
switchport nonegotiate
switchport voice vlan 55
switchport port-security maximum 2
authentication event fail action authorize vlan 100
authentication event no-response action authorize vlan 100
authentication host-mode multi-domain
authentication port-control auto
authentication violation restrict
mab
dot1x pae authenticator
dot1x timeout quiet-period 15
dot1x timeout tx-period 3
storm-control broadcast level pps 100
storm-control multicast level pps 110
no vtp
lldp receive
lldp transmit
spanning-tree portfast
no shu
exit

αž’αŸ’αž“αž€αž’αžΆαž…αž”αŸ’αžšαžΆαž€αžŠαžαžΆαž€αž»αŸ†αž–αŸ’αž™αžΌαž‘αŸαžš αž“αž·αž„αž‘αžΌαžšαžŸαž–αŸ’αž‘αžšαž”αžŸαŸ‹αž’αŸ’αž“αž€αž”αžΆαž“αž†αŸ’αž›αž„αž€αžΆαžαŸ‹αž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αžŠαŸ„αž™αž‡αŸ„αž‚αž‡αŸαž™αžŠαŸ„αž™αž”αŸ’αžšαžΎαž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆαŸ–

sh authentication sessions int Gi1/0/39 det

αž₯αž‘αžΌαžœβ€‹αž™αžΎαž„β€‹αž”αž„αŸ’αž€αžΎαžβ€‹αž€αŸ’αžšαž»αž˜ (αž§αž‘αžΆαž αžšαžŽαŸ sg-fgpp-mab ) αž“αŸ…αž€αŸ’αž“αž»αž„ Active Directory αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž‘αžΌαžšαžŸαž–αŸ’αž‘ αž αžΎαž™αž”αž“αŸ’αžαŸ‚αž˜αž§αž”αž€αžšαžŽαŸαž˜αž½αž™αž‘αŸ…αžœαžΆαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αžŸαžΆαž€αž›αŸ’αž”αž„ (αž€αŸ’αž“αž»αž„αž€αžšαžŽαžΈαžšαž”αžŸαŸ‹αžαŸ’αž‰αž»αŸ†αžœαžΆαž‡αžΆ αž αŸ’αž‚αŸ’αžšαŸαž“αžŸαŸ’αž‘αŸ’αžšαžΈαž˜αž‡αžΈαž’αŸαžŸαž—αžΈ ្៑៣០ αž‡αžΆαž˜αž½αž™αž“αžΉαž„αž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“ Mas 000b.82ba.a7b1 αž“αž·αž„αž†αŸ’αž›αžΎαž™αžαž” αž‚αžŽαž“αžΈ αžŠαŸ‚αž“ 00b82baa7b1).

αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αŸ’αžšαž»αž˜αžŠαŸ‚αž›αž”αžΆαž“αž”αž„αŸ’αž€αžΎαž αž™αžΎαž„αž“αžΉαž„αž”αž“αŸ’αžαž™αžαž˜αŸ’αžšαžΌαžœαž€αžΆαžšαž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹ (αžŠαŸ„αž™αž”αŸ’αžšαžΎ αž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž›αŸαžαžŸαž˜αŸ’αž„αžΆαžαŸ‹αž›αŸ’αž’αž·αžαž›αŸ’αž’αž“αŸ‹ αžαžΆαž˜αžšαž™αŸˆ Active Directory Administration Center -> domain -> System -> Password Settings Container) αžŠαŸ‚αž›αž˜αžΆαž“αž”αŸ‰αžΆαžšαŸ‰αžΆαž˜αŸ‰αŸ‚αžαŸ’αžšαžŠαžΌαž…αžαžΆαž„αž€αŸ’αžšαŸ„αž˜ αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹αžŸαž˜αŸ’αžšαžΆαž”αŸ‹ MAB:

αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ 802.1X αž“αŸ…αž›αžΎ Cisco Switchs αžŠαŸ„αž™αž”αŸ’αžšαžΎ Failover NPS (Windows RADIUS with AD)

αžŠαžΌαž…αŸ’αž“αŸαŸ‡ αž™αžΎαž„αž“αžΉαž„αž’αž“αž»αž‰αŸ’αž‰αžΆαžαž±αŸ’αž™αž”αŸ’αžšαžΎαž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“αž§αž”αž€αžšαžŽαŸαž’αŸ†αž‡αžΆαž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹αŸ” αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž“αŸαŸ‡ αž™αžΎαž„αž’αžΆαž…αž”αž„αŸ’αž€αžΎαžαž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž”αžŽαŸ’αžαžΆαž‰αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αž—αžΆαž–αžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœαž“αŸƒαžœαž·αž’αžΈαžŸαžΆαžŸαŸ’αžαŸ’αžš 802.1x αžŸαžΌαž˜αž αŸ…αžœαžΆαžαžΆ neag-devices-8021x-voiceαŸ” αž”αŸ‰αžΆαžšαŸ‰αžΆαž˜αŸ‰αŸ‚αžαŸ’αžšαž˜αžΆαž“αžŠαžΌαž…αžαžΆαž„αž€αŸ’αžšαŸ„αž˜αŸ–

  • αž”αŸ’αžšαž—αŸαž‘αž…αŸ’αžšαž€ NAS - ធ៊ីសឺរណិត
  • αž€αŸ’αžšαž»αž˜αžœαžΈαž“αžŠαžΌ - sg-fgpp-mab
  • αž”αŸ’αžšαž—αŸαž‘ EAPαŸ– αž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αžŠαŸ„αž™αž˜αž·αž“αž”αžΆαž“αž’αŸŠαž·αž“αž‚αŸ’αžšαžΈαž” (PAP, SPAP)
  • αž‚αž»αžŽαž›αž€αŸ’αžαžŽαŸˆ RADIUS – αž’αŸ’αž“αž€αž›αž€αŸ‹αž‡αžΆαž€αŸ‹αž›αžΆαž€αŸ‹αŸ– αžŸαŸŠαžΈαžŸαŸ’αž€αžΌ – αžŸαŸŠαžΈαžŸαŸ’αž€αžΌ-ធេវ-αž‚αžΌ – αžαž˜αŸ’αž›αŸƒαž‚αž»αžŽαž›αž€αŸ’αžαžŽαŸˆαŸ– αž§αž”αž€αžšαžŽαŸ-αž…αžšαžΆαž…αžšαžŽαŸ-αžαŸ’αž“αžΆαž€αŸ‹=αžŸαŸ†αž‘αŸαž„

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αžŠαŸ„αž™αž‡αŸ„αž‚αž‡αŸαž™ (αž€αž»αŸ†αž—αŸ’αž›αŸαž…αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž…αŸ’αžšαž€αž”αŸ’αžαžΌαžš) αžαŸ„αŸ‡αž˜αžΎαž›αž–αŸαžαŸŒαž˜αžΆαž“αž–αžΈαž…αŸ’αžšαž€αŸ–

sh authentication se int Gi1/0/34

----------------------------------------
            Interface:  GigabitEthernet1/0/34
          MAC Address:  000b.82ba.a7b1
           IP Address:  172.29.31.89
            User-Name:  000b82baa7b1
               Status:  Authz Success
               Domain:  VOICE
       Oper host mode:  multi-domain
     Oper control dir:  both
        Authorized By:  Authentication Server
      Session timeout:  N/A
         Idle timeout:  N/A
    Common Session ID:  0000000000000EB2000B8C5E
      Acct Session ID:  0x00000134
               Handle:  0xCE000EB3

Runnable methods list:
       Method   State
       dot1x    Failed over
       mab      Authc Success

αž₯αž‘αžΌαžœαž“αŸαŸ‡ αžŠαžΌαž…αžŠαŸ‚αž›αž”αžΆαž“αžŸαž“αŸ’αž™αžΆ αžŸαžΌαž˜αž€αŸ’αžšαž‘αŸαž€αž˜αžΎαž›αžŸαŸ’αžαžΆαž“αž—αžΆαž–αž˜αž½αž™αž…αŸ†αž“αž½αž“αžŠαŸ‚αž›αž˜αž·αž“αž…αŸ’αž”αžΆαžŸαŸ‹αž‘αžΆαŸ†αž„αžŸαŸ’αžšαž»αž„αŸ” αž§αž‘αžΆαž αžšαžŽαŸ αž™αžΎαž„αžαŸ’αžšαžΌαžœαž—αŸ’αž‡αžΆαž”αŸ‹αž€αž»αŸ†αž–αŸ’αž™αžΌαž‘αŸαžš αž“αž·αž„αž§αž”αž€αžšαžŽαŸαžšαž”αžŸαŸ‹αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αžαžΆαž˜αžšαž™αŸˆαž€αž»αž„αžαžΆαž€αŸ‹αžŠαŸ‚αž›αž˜αž·αž“αž’αžΆαž…αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαž„αž”αžΆαž“ (αž”αŸ’αžαžΌαžš)αŸ” αž€αŸ’αž“αž»αž„αž€αžšαžŽαžΈαž“αŸαŸ‡ αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž…αŸ’αžšαž€αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αžœαžΆαž“αžΉαž„αž˜αžΎαž›αž‘αŸ…αžŠαžΌαž…αž“αŸαŸ‡αŸ–

αž”αŸ’αžαžΌαžšαž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αž…αŸ’αžšαž€αž€αŸ’αž“αž»αž„ 802.1x host-mode multi-auth mode

interface GigabitEthernet1/0/1
description *SW – 802.1x – 8 mac*
shu
switchport mode access
switchport nonegotiate
switchport voice vlan 55
switchport port-security maximum 8  ! ΡƒΠ²Π΅Π»ΠΈΡ‡ΠΈΠ²Π°Π΅ΠΌ ΠΊΠΎΠ»-Π²ΠΎ допустимых мас-адрСсов
authentication event fail action authorize vlan 100
authentication event no-response action authorize vlan 100
authentication host-mode multi-auth  ! – Ρ€Π΅ΠΆΠΈΠΌ Π°ΡƒΡ‚Π΅Π½Ρ‚ΠΈΡ„ΠΈΠΊΠ°Ρ†ΠΈΠΈ
authentication port-control auto
authentication violation restrict
mab
dot1x pae authenticator
dot1x timeout quiet-period 15
dot1x timeout tx-period 3
storm-control broadcast level pps 100
storm-control multicast level pps 110
no vtp
spanning-tree portfast
no shu

PS αž™αžΎαž„αž”αžΆαž“αž€αžαŸ‹αžŸαž˜αŸ’αž‚αžΆαž›αŸ‹αžƒαžΎαž‰αž”αž‰αŸ’αž αžΆαž…αž˜αŸ’αž›αŸ‚αž€αž˜αž½αž™ - αž”αŸ’αžšαžŸαž·αž“αž”αžΎαž§αž”αž€αžšαžŽαŸαžαŸ’αžšαžΌαžœαž”αžΆαž“αž—αŸ’αž‡αžΆαž”αŸ‹αžαžΆαž˜αžšαž™αŸˆαž€αž»αž„αžαžΆαž€αŸ‹αž”αŸ‚αž”αž“αŸαŸ‡ αž αžΎαž™αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž˜αž€αžœαžΆαžαŸ’αžšαžΌαžœαž”αžΆαž“αžŠαŸ„αžαž…αžΌαž›αž‘αŸ…αž€αŸ’αž“αž»αž„αž€αž»αž„αžαžΆαž€αŸ‹αžŠαŸ‚αž›αž”αžΆαž“αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαž„ αž“αŸ„αŸ‡αžœαžΆαž“αžΉαž„αž˜αž·αž“αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž‘αŸαžšαž αžΌαžαžŠαž›αŸ‹αž™αžΎαž„αž”αž·αž‘αž”αžΎαž€ (!) αž€αž»αž„αžαžΆαž€αŸ‹αž‘αžΎαž„αžœαž·αž‰αŸ” αžαŸ’αž‰αž»αŸ†αž˜αž·αž“αž”αžΆαž“αžšαž€αžƒαžΎαž‰αžœαž·αž’αžΈαž•αŸ’αžŸαŸαž„αž‘αŸ€αžαž‘αŸ αžŠαžΎαž˜αŸ’αž”αžΈαžŠαŸ„αŸ‡αžŸαŸ’αžšαžΆαž™αž”αž‰αŸ’αž αžΆαž“αŸαŸ‡αž“αŸ…αž‘αžΎαž™αŸ”

αž…αŸ†αžŽαž»αž…αž˜αž½αž™αž‘αŸ€αžαž‘αžΆαž€αŸ‹αž‘αž„αž“αžΉαž„ DHCP (αž”αŸ’αžšαžŸαž·αž“αž”αžΎ ip dhcp snooping αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αŸ’αžšαžΎ) - αžŠαŸ„αž™αž‚αŸ’αž˜αžΆαž“αž‡αž˜αŸ’αžšαžΎαžŸαž”αŸ‚αž”αž“αŸαŸ‡αŸ–

ip dhcp snooping vlan 1-100
no ip dhcp snooping information option

αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž αŸαžαž»αž•αž›αž˜αž½αž™αž…αŸ†αž“αž½αž“αžŠαŸ‚αž›αžαŸ’αž‰αž»αŸ†αž˜αž·αž“αž’αžΆαž…αž‘αž‘αž½αž›αž”αžΆαž“αž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“ IP αž”αžΆαž“αžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœ... αž‘αŸ„αŸ‡αž”αžΈαž‡αžΆαžœαžΆαž’αžΆαž…αž‡αžΆαž›αž€αŸ’αžαžŽαŸˆαž–αž·αžŸαŸαžŸαžšαž”αžŸαŸ‹αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž˜αŸ DHCP αžšαž”αžŸαŸ‹αž™αžΎαž„αž€αŸαžŠαŸ„αž™αŸ”

αž αžΎαž™ Mac OS & Linux (αžŠαŸ‚αž›αž˜αžΆαž“αž€αžΆαžšαž‚αžΆαŸ†αž‘αŸ’αžš 802.1x ដើម) αž–αŸ’αž™αžΆαž™αžΆαž˜αž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ αž‘αŸ„αŸ‡αž”αžΈαž‡αžΆαž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αžŠαŸ„αž™αž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“ Mac αžαŸ’αžšαžΌαžœαž”αžΆαž“αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž€αŸαžŠαŸ„αž™αŸ”

αž“αŸ…αž€αŸ’αž“αž»αž„αž•αŸ’αž“αŸ‚αž€αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž“αŸƒαž’αžαŸ’αžαž”αž‘ αž™αžΎαž„αž“αžΉαž„αž–αž·αž“αž·αžαŸ’αž™αž˜αžΎαž›αž€αžΆαžšαž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ 802.1x αžŸαž˜αŸ’αžšαžΆαž”αŸ‹ Wireless (αž’αžΆαžŸαŸ’αžšαŸαž™αž›αžΎαž€αŸ’αžšαž»αž˜αžŠαŸ‚αž›αž‚αžŽαž“αžΈαž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž‡αžΆαž€αž˜αŸ’αž˜αžŸαž·αž‘αŸ’αž’αž· αž™αžΎαž„αž“αžΉαž„ "αž”αŸ„αŸ‡" αžœαžΆαž‘αŸ…αž€αŸ’αž“αž»αž„αž”αžŽαŸ’αžαžΆαž‰αžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž‚αŸ’αž“αžΆ (vlan) αž‘αŸ„αŸ‡αž”αžΈαž‡αžΆαž–αž½αž€αž‚αŸαž“αžΉαž„αž—αŸ’αž‡αžΆαž”αŸ‹αž‘αŸ… SSID αžŠαžΌαž…αž‚αŸ’αž“αžΆ) αŸ”

αž”αŸ’αžšαž—αž–: www.habr.com

αž”αž“αŸ’αžαŸ‚αž˜αž˜αžαž·αž™αŸ„αž”αž›αŸ‹