- Implement centralized RADIUS authentication for wireless (WPA2-Enterprise) and wired clients (802.1X).
- Configure Cisco Switch (Switch0) port-based authentication (dot1x).
- Configure RADIUS/AAA server (Server1) to service access requests.
- Set up multi-interface static routing and verify end-to-end connectivity.
| Device | Interface | IP Address / Subnet Mask | Gateway | Description |
|---|---|---|---|---|
| Router0 | Fa0/0 | 50.0.0.1/24 | Server Zone Gateway (Server0) | |
| Router0 | Fa0/1 | 40.0.0.1/24 | AAA RADIUS Gateway (Server1) | |
| Router0 | Fa1/0 | 10.0.0.1/24 | Wired LAN Gateway (Switch0) | |
| Router0 | Fa1/1 | 30.0.0.1/30 | Wireless Transit Gateway | |
| Switch0 | Vlan1 | 10.0.0.5/24 | 10.0.0.1 | Wired Access Switch (802.1X) |
| Server1 | Fa0 | 40.0.0.2/24 | 40.0.0.1 | RADIUS / AAA Server |
| Wireless Router0 | WAN | 30.0.0.2/30 | 30.0.0.1 | Access Point Gateway |
| Wireless Router0 | LAN | 20.0.0.1/24 | N/A | WLAN Local Subnet |
| PC0 / Laptops | Access Ports | Dynamic (DHCP) | Local Gateways | Authenticated Endpoints |
enable
configure terminal
! Enable AAA globally
aaa new-model
aaa authentication dot1x default group radius
! Globally enable 802.1X authentication
dot1x system-auth-control
! RADIUS Server Host Definition
radius-server host 40.0.0.2 key cisco
! Interface Management IP & Default Gateway
interface Vlan1
ip address 10.0.0.5 255.255.255.0
no shutdown
exit
ip default-gateway 10.0.0.1
! Enable 802.1X Port Authentication on FastEthernet0/5
interface FastEthernet0/5
switchport mode access
authentication port-control auto
dot1x pae authenticator
no shutdown
end
write memory
enable
configure terminal
interface FastEthernet0/0
ip address 50.0.0.1 255.255.255.0
no shutdown
interface FastEthernet0/1
ip address 40.0.0.1 255.255.255.0
no shutdown
interface FastEthernet1/0
ip address 10.0.0.1 255.255.255.0
no shutdown
interface FastEthernet1/1
ip address 30.0.0.1 255.255.255.252
no shutdown
ip route 20.0.0.0 255.255.255.0 30.0.0.2
end
write memory
Service: AAA Enabled (Port: 1645) AAA Clients Setup: Wireless | IP: 30.0.0.2 | Key: cisco switch | IP: 10.0.0.5 | Key: cisco User Database: user1 / 123 user2 / 456 user3 / 789
### 🎯 4. Wireless Router Setup (WRT300N) SSID: wifi WAN Setup: Static IP 30.0.0.2, Subnet Mask 255.255.255.252, Gateway 30.0.0.1 LAN Setup: Local IP 20.0.0.1, Subnet Mask 255.255.255.0, DHCP Enabled Security Mode: WPA2-Enterprise (Encryption: AES) RADIUS Server: 40.0.0.2 | Shared Key: cisco





