[index] SwitchBlade x3100シリーズ コマンドリファレンス
- 概要 - 認証方式 - ホストモード - 基本設定 - 802.1X認証 - MACアドレスベース認証(MACベース認証) - ダイナミックVLAN - ゲストVLAN - 認証サーバー
Note - 本製品は、同一ポート上で802.1X認証とMACベース認証を併用することはできません。
Note - 設定を開始する前に設定対象のインターフェースのSTPを無効にしてから設定を行います。STPを無効にするにはDISABLE STPコマンドのINTERFACEパラメーターを使います。また、ポート認証を有効にするとインターフェースのディレクション(CUSTOMERからNETWORK)の変更や、VLANとインターフェースとの関連付けの変更ができなくなります。
Note - インターフェースのディレクションは、CUSTOMERのみサポートしています。NETWORKはサポートしていません。インターフェースのディレクションの設定変更は、SET INTERFACE GEコマンドまたはSET INTERFACE XEコマンドで行えます。
officer SEC>> CREATE VLAN VID=4,301 ↓
officer SEC>> ADD VLAN=VLAN4 INTERFACE=1.0 ↓
officer SEC>> ADD VLAN=VLAN301 INTERFACE=1.1,6.22-6.23 ↓
officer SEC>> DISABLE STP INTERFACE=6.22-6.23 ↓
officer SEC>> ADD IP INTERFACE=VLAN:4.0 IPADDRESS=192.168.10.1 SUBNETMASK=255.255.255.0 ↓
officer SEC>> ENABLE IP INTERFACE=VLAN:4.0 ↓
officer SEC>> ADD RADIUS SERVER=192.168.10.205 SECRET=naspass1 TYPE=DOT1X AUTHENTICATION=ON RETRIES=2 PRIORITY=1 ACCOUNTING=ON ↓
officer SEC>> ADD RADIUS SERVER=192.168.10.206 SECRET=naspass2 TYPE=DOT1X AUTHENTICATION=ON RETRIES=2 PRIORITY=2 ACCOUNTING=ON ↓
officer SEC>> ADD RADIUS SERVER=192.168.10.207 SECRET=naspass3 TYPE=DOT1X AUTHENTICATION=ON PRIORITY=3 ACCOUNTING=ON ↓
officer SEC>> SET RADIUS ACCOUNTINGPERIOD=60 INTERIMUPDATE=ON ↓
officer SEC>> ENABLE DOT1X INTERFACE=6.22-6.23 ↓
officer SEC>> ENABLE DOT1X ↓
officer SEC>> SET DOT1X ACCOUNTING=STARTSTOP ↓ officer SEC>> SHOW DOT1X ↓ --- Port Authentication Information --- 802.1X ------ 802.1X Port-Based Authentication...... Enabled RADIUS Accounting..................... Start-Stop |
officer SEC>> SHOW DOT1X INTERFACE=6.22-6.23 ↓ --- Port Authentication Interface --- Interface Status PortControl HostMode GuestVLAN --------- ------------- ------------ --------- --------- ETH:6.22 Enabled Auto Single None ETH:6.23 Enabled Auto Single None officer SEC>> SHOW DOT1X SUPPLICANT ↓ --- 802.1X Port-Based Authentication Supplicant --- Authorized/Total...................... 0/ 1 --- 802.1X Port-Based Authentication Supplicant --- Interface UserName Type VLAN Status MacAddress --------- ----------------- --------- ---- -------------- ----------------- ETH:6.22 user1 802.1X 301 Authenticating 00:09:41:58:E6:F2 |
officer SEC>> CREATE VLAN VID=4,301 ↓
officer SEC>> ADD VLAN=VLAN4 INTERFACE=1.0 ↓
officer SEC>> ADD VLAN=VLAN301 INTERFACE=1.1,6.22-6.23 ↓
officer SEC>> DISABLE STP INTERFACE=6.22-6.23 ↓
officer SEC>> ADD IP INTERFACE=VLAN:4.0 IPADDRESS=192.168.10.1 SUBNETMASK=255.255.255.0 ↓
officer SEC>> ENABLE IP INTERFACE=VLAN:4.0 ↓
officer SEC>> ADD RADIUS SERVER=192.168.10.5 SECRET=stre TYPE=MACAUTH AUTHENTICATION=ON RETRIES=2 PRIORITY=1 ACCOUNTING=ON ↓
officer SEC>> ADD RADIUS SERVER=192.168.10.100 SECRET=stre2 TYPE=MACAUTH AUTHENTICATION=ON RETRIES=2 PRIORITY=2 ACCOUNTING=ON ↓
officer SEC>> ADD RADIUS SERVER=192.168.10.110 SECRET=stre3 TYPE=MACAUTH AUTHENTICATION=ON PRIORITY=3 ACCOUNTING=ON ↓
officer SEC>> SET RADIUS ACCOUNTINGPERIOD=60 INTERIMUPDATE=ON ↓
officer SEC>> SHOW RADIUS ↓ --- RADIUS -------------------------------------------------------------------- Auth Mode............................. Login Interim-Update........................ ON Accounting Period..................... 60 RADIUS Servers ------------------------------------------------------------ Hostname/IP Auth Acct Time Address Status Pri Port Port Retries out Function Type ---------------- -------- --- ----- ----- ------- ----- ---------------- ----- 192.168.10.5 Enabled 1 1812 1813 2 5 AUTHENTICATION, MACAUTH ACCOUNTING 192.168.10.100 Enabled 2 1812 1813 2 5 AUTHENTICATION, MACAUTH ACCOUNTING 192.168.10.110 Enabled 3 1812 1813 3 5 AUTHENTICATION, MACAUTH ACCOUNTING |
officer SEC>> ENABLE MACAUTHENTICATION ↓
officer SEC>> ENABLE MACAUTHENTICATION INTERFACE=6.22-6.23 ↓
officer SEC>> SET MACAUTHENTICATION ACCOUNTING=STARTSTOP ↓
officer SEC>> SHOW MACAUTHENTICATION ↓ --- MAC-Based Authentication Information --- MAC-Based Authentication..... Enabled User Name Format............. Unformatted Upper Case................... Off RADIUS Accounting............ Start-Stop |
officer SEC>> SHOW MACAUTHENTICATION INTERFACE=6.22-6.23 ↓ --- Port Authentication Interface --- Interface Status PortControl HostMode GuestVLAN --------- ------------- ------------ --------- --------- ETH:6.22 Enabled Auto Single None ETH:6.23 Enabled Auto Single None officer SEC>> SHOW MACAUTHENTICATION SUPPLICANT INTERFACE=6.22-6.23 ↓ --- MAC-Based Authentication Supplicant --- Authorized/Total...................... 2/ 2 --- MAC-Based Authentication Supplicant --- Interface Authorized/Total --------- ---------------- ETH:6.22 1/ 1 ETH:6.23 1/ 1 --- MAC-Based Authentication Supplicant --- Interface UserName Type VLAN Status MacAddress --------- ----------------- --------- ---- -------------- ----------------- ETH:6.22 00-0c-25-1a-1b-1c MAC-Based 10 Authenticated 00:0C:25:1A:1B:1C ETH:6.23 00-0c-25-aa-bb-cc MAC-Based 10 Authenticated 00:0C:25:AA:BB:CC |
user1 | password1 | VLAN(13) | IEEE-802(6) | 20 | 802.1X Supplicant用のユーザー名/パスワードおよび、認証後に所属させるVLAN |
officer SEC>> CREATE VLAN=A VID=10 ↓
officer SEC>> CREATE VLAN=B VID=20 ↓
officer SEC>> CREATE VLAN=C VID=30 ↓
officer SEC>> CREATE VLAN=R VID=1000 ↓
officer SEC>> ADD VLAN=R INTERFACE=1.23 ↓
officer SEC>> ADD IP INTERFACE=VLAN:1000.0 IPADDRESS=192.168.10.5 SUBNETMASK=255.255.255.0 ↓
officer SEC>> ENABLE IP INTERFACE=VLAN:1000.0 ↓
officer SEC>> ADD RADIUS SERVER=192.168.10.130 SECRET=himitsu TYPE=DOT1X AUTHPORT=1812 ACCTPORT=1813 AUTHENTICATION=ON ACCOUNTING=ON PRIORITY=1 ↓
officer SEC>> ENABLE DOT1X INTERFACE=1.0-1.15 ↓
officer SEC>> SET AUTHENTICATION INTERFACE=1.1-1.8 DYNAMICVLAN=SINGLE ↓
officer SEC>> ENABLE DOT1X ↓
Note - 以下の例では、802.1X認証を使用していますが、MACベース認証でも同様に動作します。
officer SEC>> CREATE VLAN=A VID=10 ↓
officer SEC>> CREATE VLAN=B VID=20 ↓
officer SEC>> ADD VLAN=A INTERFACE=1.9 ↓
officer SEC>> ADD VLAN=A INTERFACE=1.1-1.3 ↓
officer SEC>> ADD IP INTERFACE=VLAN:10.0 IPADDRESS=192.168.10.5 SUBNETMASK=255.255.255.0 ↓
officer SEC>> ADD RADIUS SERVER=192.168.10.130 SECRET=himitsu AUTHENTICATION=ON ACCOUNTING=ON TYPE=DOT1X AUTHPORT=1812 ACCTPORT=1813 PRIORITY=1 ↓
officer SEC>> ENABLE DOT1X INTERFACE=1.1-1.3 ↓
officer SEC>> SET AUTHENTICATION INTERFACE=1.1-1.3 GUESTVLAN=20 ↓
officer SEC>> ENABLE DOT1X ↓
(C) 2010-2012 アライドテレシスホールディングス株式会社
PN: 613-001335 Rev.C