Users Guide

Security Commands 1092
global shared secret and a third server 3.3.3.3 using a server specific shared
secret. CoA disconnect requests are accepted from these servers. Any
authentication type is allowed for CoA disconnect requests.
console#configure terminal
console(config)# aaa new-model
console(config)# aaa authentication dot1x default radius
console(config)# dot1x system-auth-control
console(config)# interface range gi1/0/1-24
console(config-if)# authentication port-control auto
console(config-if)# authentication host-mode multi-auth
console(config-if)# exit
console(config)# radius server auth 1.1.1.1
console(config-auth-radius)#primary
console(config-auth-radius)#exit
console(config)# radius server auth 2.2.2.2
console(config-auth-radius)#exit
console(config)# radius server auth 3.3.3.3
console(config-auth-radius)#key “That’s your secret.”
console(config-auth-radius)#exit
console(config)# radius server key “Keep it. Keep it.”
console(config)# aaa server radius dynamic-author
console(config-radius-da)# client 3.3.3.3 server-key 0 “That’s your secret.”
console(config-radius-da)# client 1.1.1.1
console(config-radius-da)# client 2.2.2.2
console(config-radius-da)# server-key 0 “Keep it. Keep it.”
console(config-radius-da)# port 3799
console(config-radius-da)# auth-type any
console(config-radius-da)# exit
console(config)#dot1x system-auth-control
console(config)#clear authentication sessions
dot1x user
Use this command to add an IAS or administrator user ID to the list of users
allowed to authenticate on an interface.
Syntax
dot1x user { user-id [ interface-id | all ]}
no dot1x user { user-id }
ias-user-id—The user name of a configured IAS user or switch
administrator.
interface-id —An interface (Ethernet) identifier.