配置3A认证服务器(WINSDOWS2016)和客户端

配置RADIUS服务器(WINDOWS 2016)和服务端

1.基础搭建

image-20250611111733194

image-20250611105309715

image-20250610221213544

2.配置AD域服务

image-20250610221416738

image-20250610221439290

image-20250610221451632

image-20250610221540156

image-20250610221643696

image-20250610221749477

image-20250610221805500

image-20250610221819475

image-20250610221839467

image-20250610222101212

image-20250610222147058

image-20250611093323179

image-20250611093407641

image-20250611093626868

image-20250611093646180

image-20250611093728629

image-20250611093807020

image-20250611093936744

安装完成后会自动重启

3.配置组策略

3.1.配置密码策略

image-20250611100005046

image-20250611100327583

image-20250611100525770

image-20250611100558840

强制刷新策略

image-20250611100650781

4.改DNS

image-20250611100750633

image-20250611100912249

5.配置RADIUS服务

image-20250611101051447

image-20250611101101257

image-20250611101111724

image-20250611101120574

5.1.配置网络策略和访问服务

image-20250611101142248

image-20250611101215548

image-20250611101239684

image-20250611101253416

image-20250611101330313

image-20250611101350117

打开网络策略服务

image-20250611101506617

5.1.1.共享机密
image-20250611101612186

image-20250611101704780

image-20250611101748029

5.1.2.配置RADIUS客户端
image-20250611101815100

image-20250611101912284

image-20250611101924814

5.1.3.配置网络策略

##–概述

image-20250611102151306

##–条件

image-20250611111234187

image-20250611111302176

image-20250611111403248

image-20250611111434888

image-20250611111456937

##–约束

image-20250611102235011

image-20250611102336530

5.2.创建用户

image-20250611102417940

5.2.1.创建一个OU
image-20250611102512790

image-20250611102544253

5.2.2.创建新用户
image-20250611102605928

image-20250611102656613

image-20250611102754577

image-20250611102813932

image-20250611102906461

6.配置3A服务客户端

AR3

<Huawei>sys    

#创建认证方案
[Huawei]aaa
[Huawei-aaa]authentication-scheme renzheng
[Huawei-aaa-authen-renzheng]authentication-mode radius
[Huawei-aaa-authen-renzheng]quit

#创建计费方案
[Huawei-aaa]accounting-scheme jifei
[Huawei-aaa-accounting-jifei]accounting-mode radiu
[Huawei-aaa-accounting-jifei]accounting start-fail offline 
[Huawei-aaa-accounting-jifei]quit

#创建RADIUS服务器模板
[Huawei]radius-server template Windows2016
[Huawei-radius-Windows2016]radius-server authentication 192.168.80.129 1812
[Huawei-radius-Windows2016]radius-server accounting 192.168.80.129 1813
[Huawei-radius-Windows2016]radius-server shared-key cipher 51cto
[Huawei-radius-Windows2016]radius-server retransmit 2 timeout 5
[Huawei-radius-Windows2016]quit

#创建域
[Huawei]aaa
[Huawei-aaa]domain 51cto.com
[Huawei-aaa-domain-51cto.com]authentication-scheme renzheng  #添加认证方案
[Huawei-aaa-domain-51cto.com]accounting-scheme jifei         #添加计费方案
[Huawei-aaa-domain-51cto.com]radius-server Windows2016       #添加连接模块
[Huawei-aaa-domain-51cto.com]quit
[Huawei-aaa]quit

#添加通讯地址
[Huawei]display ip interface brief
[Huawei]interface GigabitEthernet 0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 192.168.80.111 24
[Huawei-GigabitEthernet0/0/0]quit

#创建远程登录
[Huawei]user-interface vty 0 4
[Huawei-ui-vty0-4]authentication-mode aaa
[Huawei-ui-vty0-4]user privilege level 3
[Huawei-ui-vty0-4]quit

[Huawei]display current-configuration 
[V200R003C00]
#
 snmp-agent local-engineid 800007DB03000000000000
 snmp-agent 
#
 clock timezone China-Standard-Time minus 08:00:00
#
portal local-server load portalpage.zip
#
 drop illegal-mac alarm
#
 set cpu-usage threshold 80 restore 75
#
radius-server template Windows2016
 radius-server shared-key cipher %$%$~R$Z#o0joVs>T`=Ep;N="Qo8%$%$
 radius-server authentication 192.168.80.129 1812
 radius-server accounting 192.168.80.129 1813
 radius-server retransmit 2
#
aaa 
 authentication-scheme default
 authentication-scheme renzheng
  authentication-mode radius
 authorization-scheme default
 accounting-scheme default
 accounting-scheme jifei 
  accounting-mode radius
 domain default 
 domain default_admin 
 domain 51cto.com  
  authentication-scheme renzheng 
  accounting-scheme jifei 
  radius-server Windows2016
 domain 51cto 
 local-user admin password cipher %$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
 local-user admin service-type http

7.测试

是否能通讯

image-20250611105347524

安装telnet

image-20250611110131639

远程登录测试

image-20250611111709183

image-20250611111551721

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注