最强网络准入开源软件-Packetfence-H3C交换机准入配置(三)






#version 7.1.075#sysname H3C_S5820V2#dot1x authentication-method eap //配置802.1X系统的认证方法为EAP中继方式#mac-authentication domain packetfence //定MAC认证用户所使用的认证域packetfence#port-security enable //开启端口安全功能port-security mac-move permit //开启允许MAC迁移功能#dhcp snooping enable#lldp global enable#system-working-mode standardxbar load-singlepassword-recovery enablelpu-type f-series#vlan 1#vlan 2#vlan 5#vlan 1000 //用户接入vlan,无需注册vlan及隔离vlan#stp global enable#interface NULL0#interface Vlan-interface1000ip address 10.10.1.254 255.255.255.0 //用户vlan网关地址#interface FortyGigE1/0/53port link-mode bridge#interface FortyGigE1/0/54port link-mode bridge#interface GigabitEthernet1/0/1port link-mode routecombo enable copperip address 192.168.18.72 255.255.255.0##interface GigabitEthernet1/0/2 //端口下相关配置,需要认证的商品都一样的配置port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10mac-authentication re-authenticate server-unreachable keep-onlinemac-authentication guest-vlan 1000port-security intrusion-mode blockmacport-security max-mac-count 10port-security port-mode mac-authentication#interface GigabitEthernet1/0/3port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10mac-authentication re-authenticate server-unreachable keep-onlinemac-authentication guest-vlan 1000port-security intrusion-mode blockmacport-security max-mac-count 10port-security port-mode mac-authentication#interface GigabitEthernet1/0/4port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10mac-authentication re-authenticate server-unreachable keep-onlinemac-authentication guest-vlan 1000port-security intrusion-mode blockmacport-security max-mac-count 10port-security port-mode mac-authentication#interface GigabitEthernet1/0/5port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10mac-authentication re-authenticate server-unreachable keep-onlinemac-authentication guest-vlan 1000port-security intrusion-mode blockmacport-security max-mac-count 10port-security port-mode mac-authentication#interface GigabitEthernet1/0/6port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10mac-authentication re-authenticate server-unreachable keep-onlinemac-authentication guest-vlan 1000port-security intrusion-mode blockmacport-security max-mac-count 10port-security port-mode mac-authentication#interface GigabitEthernet1/0/7port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10mac-authentication re-authenticate server-unreachable keep-onlinemac-authentication guest-vlan 1000port-security intrusion-mode blockmacport-security max-mac-count 10port-security port-mode mac-authentication#interface GigabitEthernet1/0/8port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10mac-authentication re-authenticate server-unreachable keep-onlinemac-authentication guest-vlan 1000port-security intrusion-mode blockmacport-security max-mac-count 10port-security port-mode mac-authentication#interface GigabitEthernet1/0/9port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10mac-authentication re-authenticate server-unreachable keep-onlinemac-authentication guest-vlan 1000port-security intrusion-mode blockmacport-security max-mac-count 10port-security port-mode mac-authentication#interface GigabitEthernet1/0/10port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10mac-authentication re-authenticate server-unreachable keep-onlinemac-authentication guest-vlan 1000port-security intrusion-mode blockmacport-security max-mac-count 10port-security port-mode mac-authentication#interface GigabitEthernet1/0/11port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/12port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/13port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/14port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/15port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/16port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/17port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/18port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/19port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/20port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/21port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/22port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/23port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/24port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/25port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/26port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/27port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/28port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/29port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/30port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/31port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/32port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/33port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/34port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/35port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/36port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/37port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/38port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/39port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/40port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/41port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/42port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/43port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/44port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/45port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/46port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/47port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#interface GigabitEthernet1/0/48port link-mode bridgeport link-type hybridundo port hybrid vlan 1port hybrid vlan 1000 untaggedport hybrid pvid vlan 1000mac-vlan enablecombo enable copperstp edged-portmac-authentication max-user 10#ip route-static 0.0.0.0 0 192.168.18.254#snmp-agentsnmp-agent local-engineid 800063A2803ABBA892010000000001snmp-agent community write privatesnmp-agent community read publicsnmp-agent sys-info version allsnmp-agent target-host trap address udp-domain 192.168.18.73 params securityname public v2c#ssh server enable#radius scheme packetfence //radius认证相关配置primary authentication 192.168.18.73 key cipher $c$3$tH+LwFV7hazjchKxC6wBNEwMD65THyH3IcUeprimary accounting 192.168.18.73 key cipher $c$3$8RbXGBT3aooZyOkFZOfWK7enwl8KXrmxPqxNuser-name-format without-domain#radius scheme pfnacprimary authentication 192.168.18.73 key cipher $c$3$DMG8ZxqWiPtyBi/VEqmpOSfeRN/JwbE4KXivprimary accounting 192.168.18.73 key cipher $c$3$HB+G8Cuf84WEY8vZsPBsq+RCdgjcPD7sDkeLuser-name-format without-domain#radius scheme systemuser-name-format without-domain#domain name packetfence //认证域配置authentication lan-access radius-scheme packetfenceauthorization lan-access radius-scheme packetfenceauthentication default radius-scheme packetfence#domain name pfnacauthentication lan-access radius-scheme pfnacauthorization lan-access radius-scheme pfnacauthentication default radius-scheme pfnac#domain name system#domain default enable system#







夜雨聆风