ÇÖȨͶËß
¶©ÔÄ
¾À´í
¼ÓÈë×ÔýÌå

ÍøÂç²âÊÔ¼¼Êõ¡ª¡ª802.1X_MD5ÈÏÖ¤£¨ÉÏ£©

Ò»¡¢MD5ÈÏÖ¤¼ò½é

1£®ÈÏÖ¤¹ý³Ì

£¨1£©ÎÞËíµÀ

£¨2£©¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼ä½øÐÐ

2£®µ¥ÏòÈÏÖ¤

£¨1£©·þÎñÆ÷¶Ô¿Í»§¶ËÈÏÖ¤

3£®È±µã

£¨1£©Óû§ÃûÃ÷ÎÄ´«Êä

£¨2£©ÈõMD5¹þÏ£


image.png

¶þ¡¢MD5ÈÏÖ¤¹ý³Ì

1£®¿Í»§¶ËÏò½»»»»ú·¢ËÍÒ»¸öEAPoL£­Start±¨ÎÄ£¬¿ªÊ¼802£®1xÈÏÖ¤½ÓÈ룻

2£®½»»»»úÏò¿Í»§¶Ë·¢ËÍEAP£­Request£¯Identity±¨ÎÄ£¬ÒªÇó¿Í»§¶Ë½«Óû§ÃûËÍÉÏÀ´£»

3£®¿Í»§¶Ë»ØÓ¦Ò»¸öEAP£­Response£¯Identity¸ø½»»»»úµÄÇëÇ󣬯äÖаüÀ¨Óû§Ãû£»

4£®½»»»»ú½«EAP£­Response£¯Identity±¨ÎÄ·â×°µ½RADIUSAccess£­Request±¨ÎÄÖУ¬·¢Ë͸øÈÏÖ¤·þÎñÆ÷£»

5£®ÈÏÖ¤·þÎñÆ÷²úÉúÒ»¸öChallenge£¬Í¨¹ý½»»»»ú½«RADIUSAccess£­Challenge±¨ÎÄ·¢Ë͸ø¿Í»§¶Ë£¬ÆäÖаüº¬ÓÐEAP£­Request£¯MD5£­Challenge£»

6£®½»»»»úͨ¹ýEAP£­Request£¯MD5£­Challenge·¢Ë͸ø¿Í»§¶Ë£¬ÒªÇó¿Í»§¶Ë½øÐÐÈÏÖ¤£»

7£®¿Í»§¶ËÊÕµ½EAP£­Request£¯MD5£­Challenge±¨Îĺ󣬽«ÃÜÂëºÍChallenge×öMD5Ëã·¨ºóµÄChallenged£­Pass£­word£¬ÔÚEAP£­Response£¯MD5£­Challenge»ØÓ¦¸ø½»»»»ú£»

8£®½»»»»ú½«Challenge£¬ChallengedPasswordºÍÓû§ÃûÒ»ÆðË͵½RADIUS·þÎñÆ÷£¬ÓÉRADIUS·þÎñÆ÷½øÐÐÈÏÖ¤£»

9£®RADIUS·þÎñÆ÷¸ù¾ÝÓû§ÐÅÏ¢£¬×öMD5Ëã·¨£¬ÅжÏÓû§ÊÇ·ñºÏ·¨£¬È»ºó»ØÓ¦ÈÏÖ¤³É¹¦£¯Ê§°Ü±¨Îĵ½½»»»»ú£»

10£®½»»»»ú´ò¿ª¶Ë¿Ú£»

11£®½»»»»ú½«EAPÈÏÖ¤³É¹¦±¨ÎÄ·¢Ë͸ø¿Í»§¶Ë


image.png

Èý¡¢½»»»»úÈÏ֤ģʽ

1£®MACÈÏ֤ģʽ

£¨1£©¸ÃģʽÏÂÁ¬½Óµ½Í¬Ò»¶Ë¿ÚµÄÿ¸öÉ豸¶¼ÐèÒªµ¥¶À½øÐÐÈÏÖ¤£»

£¨2£©»ªÎª½»»»»úĬÈÏģʽ¡£

2£®¶Ë¿ÚÈÏ֤ģʽ

£¨1£©Ö»ÒªÁ¬½Óµ½¶Ë¿ÚµÄij¸ö¿Í»§¶Ëͨ¹ýÈÏÖ¤£»

£¨2£©ÆäËü¿Í»§¶ËÔò²»ÐèÒªÈÏÖ¤£¬¾Í¿ÉÒÔ·ÃÎÊÍøÂç×ÊÔ´¡£


image.png

ËÄ¡¢²âÊÔ×éÍø

1£®×éÍøËµÃ÷

£¨1£©½»»»»úʹÓûªÎªµÄS5720£»

£¨2£©·þÎñÆ÷²ÉÓÿªÔ´µÄFreeradius£»

£¨3£©²âÊÔÒǺͽ»»»»úÁ½¸ö½Ó¿ÚÏàÁ¬£¬²¢ÇÒÔÚͬһ¸öVLANÀ

£¨4£©ÔÚ½»»»»úG0£¯0£¯1½Ó¿ÚÆôÓÃDOT1X¡£

2£®²âÊÔ˼·

£¨1£©²âÊÔÒÇP1ÏòP2·¢ËÍÁ½ÌõÁ÷Á¿£ºDOT1X£­Traffic£¬Back£­Traffic£¬Ô´MAC·Ö±ðΪ0000£­0011£­1111£¬ £¨2£©00£­0000£­0022£­2222£¬³õʼÇé¿öÏÂÁ½ÌõÁ÷Á¿¶¼²»Í¨£»

£¨3£©²âÊÔÒÇP1Ä£ÄâDOT1X¿Í»§¶Ë£¬Ô´MACµØÖ·ÊÇ0000£­0011£­1111£¬ºÍ·þÎñÆ÷½øÐÐ MD5ÈÏÖ¤£»

£¨4£©Èç¹ûÈÏ֤ͨ¹ý£¬Á÷DOT1X£­ClientÄÜͨ


image.png


Îå¡¢²âÊÔ»·¾³×¼±¸

1£®»ªÎª½»»»»úÅäÖÃ

ÅäÖÃRadiusÈÏÖ¤£¨´«Í³Ä£Ê½£©

undo authentication unified£­mode

££

radius£­server template radTem

radius£­server shared£­key cipher xinertel

radius£­server authentication 80£®1£®1£®3 1812 weight 80

££

aaa

authentication£­scheme radTemp

authentication£­mode radius

domain dot1x

authentication£­scheme radTemp

radius£­server radTem

££

È«¾ÖÅäÖÃDOT1X

domain dot1x

££

dot1x enable

££

dot1x authentication£­method eap

££

½Ó¿ÚÅäÖÃ

££

interface GigabitEthernet0£¯0£¯1

port link£­type access

port default vlan 2

dot1x enable £¯£¯½Ó¿ÚÅäÖÃdot1x

££

interface GigabitEthernet0£¯0£¯2

port link£­type access

port default vlan 2

££

interface GigabitEthernet0£¯0£¯3

undo portswitch

ip address 80£®1£®1£®1 255£®255£®255£®0

££

2£®²é¿´½»»»»ú½Ó¿ÚµÄDOT1XÐÅÏ¢

½Ó¿ÚÐÅÏ¢

£¨1£©802£®1XʹÄÜ

£¨2£©Ä¬ÈÏÊÇMAC£­based

£¨3£©ÈÏ֤ģʽÊÇEAP


image.png

3£®ÅäÖÃǰ׼±¸£º²é¿´½»»»»úDOT1Xͳ¼ÆÐÅÏ¢


image.png

4£®FreeradiusÅäÖÃ

ÐÞ¸ÄClientµÄÅäÖÃ

£¨1£©Îļþ£º£¯etc£¯raddb£¯clients£®conf

£¨2£©Ìí¼ÓÈçÏÂÄÚÈÝ

£¨3£©SecretÒªºÍ½»»»»úÉÏÅäÖÃÏàͬ


image.png

ÐÞ¸ÄeapÅäÖÃ

£¨1£©Îļþ£º£¯etc£¯raddb£¯mods£­available£¯eap

£¨2£©ÐÞ¸ÄĬÈÏÈÏÖ¤ÀàÐÍΪmd5


image.png

5£®Freeradius²âÊÔ

´ò¿ª²âÊÔÕ˺ţºÐÞ¸ÄeapÅäÖÃ

£¨1£©Îļþ£º£¯etc£¯raddb£¯users

£¨2£©È¥µôÏÂÃæÄÚÈݵÄ×¢ÊÍ


image.png

ÒÔDebugģʽÆô¶¯Freeradius


image.png

Èç¹û³öÏÖÈçϵĻظ´£¬ÔòÅäÖóɹ¦


image.png

6£®MariaDBÅäÖÃ

ÐÞ¸ÄFreeradiusÖеÄÊý¾Ý¿âÀàÐÍ

£¨1£©Îļþ£º£¯etc£¯raddb£¯mods£­available£¯sql

£¨2£©È¥µôÏÂÃæÄÚÈݵÄ×¢ÊÍ


image.png

ÔÚMariaDBÖÐÌí¼ÓÕ˺Å


image.png

ʹÓÃÐÂÌí¼ÓµÄÄÚÈݲ鿴


image.png

7£®×îºó²âÊÔ

»·¾³´î½¨ºÃ±êʶ£¬ÔÚ»ªÎª½»»»»úÖвâÊÔͨ¹ý


image.png

ÉùÃ÷£º±¾ÎÄÓÉÈëפά¿ÆºÅµÄ×÷Õß׫д£¬¹Ûµã½ö´ú±í×÷Õß±¾ÈË£¬²»´ú±íOFweekÁ¢³¡¡£ÈçÓÐÇÖȨ»òÆäËûÎÊÌ⣬ÇëÁªÏµ¾Ù±¨¡£

·¢±íÆÀÂÛ

¹² 0ÌõÆÀÂÛ£¬ 0È˲ÎÓë

ÇëÊäÈëÆÀÂÛÄÚÈÝ...

ÇëÊäÈëÆÀÂÛ/ÆÀÂÛ³¤¶È6~500¸ö×Ö

ÄúÌá½»µÄÆÀÂÛ¹ýÓÚÆµ·±£¬ÇëÊäÈëÑéÖ¤Âë¼ÌÐø

ÔÝÎÞÆÀÂÛ

ÔÝÎÞÆÀÂÛ

¹âͨѶ ÁÔͷְλ ¸ü¶à
    ÎÄÕ¾À´í
    x
    *ÎÄ×Ö±êÌ⣺
    *¾À´íÄÚÈÝ£º
    ÁªÏµÓÊÏ䣺
    *Ñé Ö¤ Â룺

    ÔÁ¹«Íø°²±¸ 44030502002758ºÅ