version 5
|
|
V5 NPS
|
||
汇聚、接入层交换机都刷(除核心两台)
|
Radius
|
radius scheme cams
primary authentication 10.116.219.43
key authentication simple 123456
nas-ip 10.118.0.158
server-type extended
user-name-format without-domain
quit
domain sf
authentication default radius-scheme cams local
authorization default radius-scheme cams local
accounting default none
quit
domain default enable sf
|
NPS域
|
radius scheme nps
server-type extended
primary authentication 10.118.88.32 key 123456
primary accounting 10.118.88.32 key 123456
user-name-format without-domain
nas-ip 10.118.0.13
domain nps
authentication default radius-scheme nps local
authorization default radius-scheme nps local
accounting default none
authentication lan-access radius-scheme nps local
authorization lan-access radius-scheme nps local
accounting lan-access radius-scheme nps local
|
SSH远程
|
public-key local create rsa
输入:1024
ssh server enable
|
MAC认证
|
mac-authentication
mac-authentication domain nps
|
|
NTP
|
ntp-service unicast-server 10.116.48.104
|
端口配置
|
interface GigabitEthernet1/0/16
mac-authentication
|
|
Console
|
user-interface aux 0
authentication-mode password
set authentication password cipher OAadmin@147
idle-timeout 5 0
quit
|
|
|
|
接入层IDLE时间
|
时间为60,仅适用于接入
|
user-interface vty 0 4
authentication-mode scheme
protocol inbound all
idle-timeout 60 0
|
|
|
汇聚层IDLE时间
|
|
user-interface vty 0 4
authentication-mode scheme
idle-timeout 15 0
|
|
|
|
|
|
|
|
|
|
|
|
|
version 3
|
|
V3 NPS
|
||
汇聚、接入层交换机都刷(除核心两台)
|
Radius
|
radius scheme cams
primary authentication 10.116.219.43
key authentication simple 123456
nas-ip 10.118.0.158
server-type extended
user-name-format without-domain
quit
domain sf
authentication default radius-scheme cams local
accounting none
quit
domain default enable sf
|
NPS 域
|
radius scheme nps
server-type extended
primary authentication 10.118.88.32
primary accounting 10.118.88.32
key authentication 123456
key accounting 123456
user-name-format without-domain
nas-ip 10.118.0.130
domain nps
scheme radius-scheme nps local
quit
|
SSH远程
|
public-key local create rsa
输入:1024
ssh authentication-type default all
|
MAC认证
|
mac-authentication
mac-authentication domain nps
mac-authentication user-name-format mac-address without-hyphen lowercase
|
|
NTP
|
ntp-service unicast-server 10.116.48.104
|
端口配置
|
int e1/0/*
mac-authentication interface Ethernet 1/0/31
|
|
Console
|
user-interface aux 0
authentication-mode password
set authentication password cipher OAadmin@147
idle-timeout 5 0
quit
|
|
|
|
接入层IDLE时间
|
时间为60,仅适用于接入
|
user-interface vty 0 4
authentication-mode scheme
protocol inbound all
idle-timeout 60 0
|
|
|
汇聚层IDLE时间
|
|
user-interface vty 0 4
authentication-mode scheme
idle-timeout 15 0
|
|
|