試驗目的:登錄路由器的時候,需要輸入你自己的用戶名和密碼,通過radius驗證通過之后,再允許登錄路由器。
配置文件如下,每個路由器都一樣的配置
R2503>en
Password:
R2503#sh run
Building configuration...
Current configuration:
!
version 12.0
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname R2503
!
aaa new-model (開啟aaa功能)
aaa authentication login ciscoclub radius (設置認證方式為radius認證,ciscoclub為認證策略名)
enable secret 5 $1$7Itz$DfIumP6x7ctddLF8QIFtF/
!
ip subnet-zero
!
interface Ethernet0
ip address 192.168.0.203 255.255.255.0
no ip directed-broadcast
!
interface Serial0
no ip address
no ip directed-broadcast
no ip mroute-cache
shutdown
!
interface Serial1
ip address 172.16.20.1 255.255.255.0
no ip directed-broadcast
clockrate 64000
!
interface BRI0
no ip address
no ip directed-broadcast
shutdown
!
ip classless
!
radius-server host 192.168.0.1?。ㄔO置radius的ip地址)
radius-server key ciscoclub (設置路由器與radius之間的密碼)
!
line con 0
transport input none
line aux 0
line vty 0 4
login authentication ciscoclub (在這里應用認證策略)
end
R2503#