Home > AAAdot1x Lab Sim

AAAdot1x Lab Sim

March 3rd, 2017 in Lab Sim, LabSim Go to comments

Question

Answer and Explanation

 

1) Configure ASW1

Enable AAA on the switch:
ASW1(config)#
aaa new-model

The new-model keyword refers to the use of method lists, by which authentication methods and sources can be grouped or organized.

Define the server along with its secret shared password:
ASW1(config)#radius-server host 172.120.39.46 key rad123

ASW1(config)#aaa authentication dot1x default group radius
This command causes the RADIUS server defined on the switch to be used for 802.1x authentication.

Globally enable port-based authentication (802.1x) on a switch:
ASW1(config)#dot1x system-auth-control

Configure Fa0/1 to use 802.1x:

ASW1(config)#interface fastEthernet 0/1
ASW1(config-if)#dot1x port-control auto
Notice that the word “auto” will force connected PC to authenticate through the 802.1x exchange.

2) Configure DSW1:

Define an access-list:
DSW1(config)#ip access-list standard 10 (syntax: ip access-list {standard | extended} acl-name)
DSW1(config-std-nacl)#permit 172.120.40.0 0.0.0.255
DSW1(config-std-nacl)#exit

Define an access-map which uses the access-list above:
DSW1(config)#vlan access-map MYACCMAP 10 (syntax: vlan access-map map_name [0-65535] )
DSW1(config-access-map)#match ip address 10 (syntax: match ip address {acl_number | acl_name})
DSW1(config-access-map)#action forward
DSW1(config-access-map)#exit

DSW1(config)#vlan access-map MYACCMAP 20
DSW1(config-access-map)#action drop (drop other networks)
DSW1(config-access-map)#exit

Apply a vlan-map into a vlan:
DSW1(config)#vlan filter MYACCMAP vlan-list 20 (syntax: vlan filter mapname vlan-list list)

DSW1#copy running-config startup-config

(Notice: Many reports said the copy running-config startup-config didn’t work but they still got the full mark)

Note: If the requirement of this sim states that “not to use named ACLs” then you should configure number ACL instead:

DSW1(config)#access-list 10 permit 172.120.40.0 0.0.0.255

Other lab-sims in this site:

LACP with STP Sim
MLS and EIGRP Sim
VTP Lab 2
VTP Lab
Spanning Tree Lab Sim

Comments
Comment pages
1 38 39 40 41
  1. John
    August 28th, 2017

    Please update the latest dump i really required

  2. Anonymous
    August 28th, 2017

    hi guys i have exam so sooon can you send me latest dumps … emai : m 7 m d 1 4 1 @ g m a i l . c o m

  3. Anonymous
    August 29th, 2017

    Passleader has updated switch to 435q. Does anyone have a copy.

  4. Shk
    August 29th, 2017

    How do you setup an access list without named ACL ? Please can anyone write out the full syntax ?

  5. Billy
    August 30th, 2017

    Hi guys any dumps available? My email Dagnicyrille(@) Gmail dot com

  6. Anonymous
    August 30th, 2017

    Anyone with Passleader 435q please share

  7. Chingy
    August 31st, 2017

    Hi guys, top tip. Listen to the whole ‘CBT-Nuggets-300-115 SWITCH’ on x2 speed. If you already have knowledge of the subject this will fill in a lot of gaps and allow you to pass the exam. On x 2 speed you should be able to watch the whole lot in approx 4.5 hours, well worth it.

  8. John
    September 1st, 2017

    Can you please help me to pass my exam please help me and share the latest dump and the complete Topology, so i can practice or email me at itmann @ outlook dot com, i will really appreciate for this help

  9. moy_switch
    September 5th, 2017

    can you also help me, i’ll take the exam next week. kindly share dumps to kamielle_33 at yahoo dot com dot ph. thank you

  10. Anonymous
    September 5th, 2017

    hello guys, taking the exam soon could you please send me the latest dumps E-mail {email not allowed}

  11. Anonymous
    September 5th, 2017

    hello guys, taking the exam soon could you please send me the latest dumps E-mail 23bold23@gmail

  12. Krabby
    September 6th, 2017

    Anyone with a copy of Passleader 435q PDF or VCE they can share here?

  13. Anonymous
    September 7th, 2017

    Anyone, Could you send ccnp switch lasted dumps and pdf
    emils=ayekyaw.simplelife@gmail

  14. chirp
    September 7th, 2017

    i think you need ”switchport port-security” on interface fa0/1 for the dot1x command?

  15. CertPrep Nickname
    September 10th, 2017

    For ASW1, is it possible to enable dot1x first?

    ASW1(config)#dot1x system-auth-control

    Because this makes sense to me logically rather than doing it towards the end, but will this still be right in the exam?

  16. PAUL
    September 11th, 2017

    Sam can you share you dump with me I taking the test this week, 23bold23 at gmail

  17. Some Guy
    September 13th, 2017

    Passed today. This lab is 100% accurate as to what was on the exam.

  18. Anonymous
    September 13th, 2017

    Dear (Some Guy) which dump you practice can you please explain more….

  19. LarBear
    September 13th, 2017

    Passed yesterday with minimum score allowed. On the simlet I added the action>drop follow up command, although I’m not sure it’s required as I think it is implied. Not sure if I got dinged for that or not.

  20. Anonymous
    September 13th, 2017

    Dear (LarBear) which dump you practice can you please explain more….

  21. PAUL
    September 13th, 2017

    Taking exam weeken,Please share the 435qns dumps to my email – 23bold23 @ gmail. com

  22. Rick
    September 16th, 2017

    ciscoexam007 @ yahoo.com , please share 435 qns . Kindly remove spaces in email ID

  23. Anonymous
    September 17th, 2017

    HI
    I am going to take switch 300-115 exam. Kindly share latest pdf file on the below address amin.asna89 @ gmail.com

    Thanks

  24. mubashir
    September 17th, 2017

    please share me also mubashirali1987 @ gmail.com

  25. Anonymous
    September 17th, 2017

    share latest switch dumps, writing next week

  26. a
    September 18th, 2017

    share latest switch dumps, writing next week

  27. omar
    September 19th, 2017

    please share me latest switch dump 435 Q omarabdela @ gmail.com and remove spaces in email ID

  28. karl
    September 20th, 2017

    please share me also my e-mail is
    {email not allowed}

  29. karl
    September 20th, 2017

    Cfernandez.vc @ gmail.com

  30. jonny
    September 26th, 2017

    hi Guys

    where can i find the network diagram for AAA lab sim , it only shows the configuration part here

  31. Tetrapole
    September 28th, 2017

    Can someone please share latest dumps. Thanks in advance.
    talal.ibr@ outlook.com

  32. suicidenetworker
    September 30th, 2017

    @jonny, go to FAQs & Tips and u will found it

  33. Rem
    October 5th, 2017

    Hi Guys,

    Good day. Can you also give me the latest dumps for CCNP Switch my email is gimeyl123 @ gmail . com

  34. Anonymous
    October 5th, 2017

    I am going to take switch 300-115 exam. Kindly share latest pdf file on the below address keol1719 @ gmail.com

  35. Bryan
    October 7th, 2017

    Could someone please share latest dumps. Thank you so much
    hoxxx345 @ umn . edu

  36. Anonymous
    October 7th, 2017

    Hi,

    Exam on Monday – latest info would be great: chillin_101uk @ yahoo . co . uk

  37. Anonymous
    October 15th, 2017

    Hey everyone, I tried to add the sequence number after the VLAN access-map (vlan access-map MYACCMAP “10”) but it didn’t allow me put the number “10”. Has anyone faced similar issues?

    Thank you

  38. Mac 2.0
    October 16th, 2017

    Hi,

    Can someone please send me the latest dumps for CCNP Switch my email is mgwigwis @ gmail.com

Comment pages
1 38 39 40 41
  1. No trackbacks yet.