1: H3C WAC360配置安全
radius scheme radius primary authentication 192.168.90.12 key authentication simple 123123 user-name-format without-domain domain radius authentication lan-access radius-scheme radius authorization lan-access radius-scheme radius access-limit disable state active idle-cut disable self-service-url disable wlan service-template 4 crypto ssid Office WiFi bind WLAN-ESS 3 cipher-suite ccmp security-ie rsn service-template enable interface WLAN-ESS3 port link-type hybrid port hybrid vlan 1 10 untagged port hybrid pvid vlan 10 mac-vlan enable port-security port-mode userlogin-secure-ext port-security tx-key-type 11key undo dot1x handshake dot1x mandatory-domain radius mac-authentication domain system dot1x authentication-method eap
2:win2012 NPS配置bash
直接添加网络策略网络
策略1:条件 Machine Groups 和 NAS Port Type 其它能够默认dom
策略2:条件 User Groups 和 NAS Port Type 其它能够默认ide
后面的认证方法,直接 EAP,下面安全就 CHAP 相关的勾上ui
添加NPS客户端,地址为 AC 的IP,密钥要和h3c一致url