FreeRADIUS EAP-TLS for Wired 802.1X with Cisco Switches - 夜莺博客

FreeRADIUS EAP-TLS for Wired 802.1X with Cisco Switches

Wired 802.1X is the control that stops an unauthorised laptop from getting a working
switch port, and FreeRADIUS is the open-source server most people deploy for it. The hard part
is not RADIUS itself, it is the certificate chain and the two-sided configuration: the server
must trust the client certificate, the client must trust the server certificate, and the switch
in the middle must be a RADIUS client with the right shared secret. This guide sets up
EAP-TLS end to end on a Cisco access switch, with the exact files and commands, plus the
troubleshooting path when the port stays in the wrong state.

Prerequisites and Certificates

EAP-TLS authenticates with certificates on both sides, so you need a CA and at least three
certificates: the CA itself, a server certificate for the RADIUS host, and a client certificate
per device. FreeRADIUS ships scripts that generate a test CA quickly, and the standard file set
is:

  • ca.pem — the CA certificate used to validate supplicants
  • server.pem / server.key — the RADIUS server's identity
  • client.pem / client.key — installed on the endpoint

The server certificate's common name is what clients validate. If you tell clients to expect
frad01.lab.local, the certificate must contain that name — in the CN or, better,
in a subjectAltName.

Step 1: Declare the Switch as a RADIUS Client

# /etc/freeradius/3.0/clients.conf   (path is /etc/freeradius/clients.conf on 4.x)
client dot1x-sw01 {
    ipaddr = 192.168.0.180
    secret = cisco123
    shortname = dot1x-sw01
    nas_type = cisco
}

Every authenticator must be listed. A switch that is not in clients.conf gets
no response at all, which the switch reports as RADIUS timeout rather than an
authentication failure.

Step 2: Enable EAP-TLS

# /etc/freeradius/3.0/mods-available/eap
eap {
    default_eap_type = tls

    tls-config tls-common {
        private_key_file     = /etc/freeradius/3.0/certs/frad01.lab.local.key
        certificate_file     = /etc/freeradius/3.0/certs/frad01.lab.local.cer
        ca_file              = /etc/freeradius/3.0/certs/lab-root-ca.cer
        private_key_password = whatever
    }

    tls {
        tls = tls-common
    }
}

Leave md5 out of the type list. EAP-MD5 provides no server authentication and
is deprecated for a reason.

Check the receive path in the default virtual server. The eap module must be
called in recv Access-Request with early return, otherwise modules such as
ldap or sql run on every round-trip of the TLS handshake instead of
only on the final packet:

recv Access-Request {
    eap {
        ok      = return
        updated = return
    }
}

authenticate eap {
    eap
}

Remember that EAP only authenticates. Authorisation — VLAN assignment, ACL return
attributes — is a separate step handled by other modules or by
post-auth.

Step 3: Configure the Cisco Access Switch

! Enable AAA
aaa new-model

! Radius server object
radius server frad01
 address ipv4 192.168.0.181 auth-port 1812 acct-port 1813
 timeout 2
 retransmit 1
 key cisco123

! Group and method lists
aaa group server radius dot1x-auth
 server name frad01

aaa authentication dot1x default group dot1x-auth
aaa authorization network default group dot1x-auth
aaa accounting dot1x default start-stop group dot1x-auth

! Source interface for RADIUS packets
ip radius source-interface Vlan1

! Globally enable 802.1X
dot1x system-auth-control

! The port itself
interface GigabitEthernet1/0/1
 switchport mode access
 switchport access vlan 10
 authentication port-control auto
 authentication host-mode multi-auth
 dot1x pae authenticator
 spanning-tree portfast

Two platform notes from real deployments: older fixed-configuration switches (the 3750-X
family is a well-known example) can fail to relay the Access-Request even though the client's
EAP-Response is visible on the port, and authentication host-mode multi-auth is
usually what you want on a port with a phone and a PC behind it.

Step 4: Verify

! On the switch
show authentication sessions interface GigabitEthernet1/0/1
show dot1x interface GigabitEthernet1/0/1 details
show authentication registrations
show radius statistics

! On the RADIUS server
radiusd -X                                   # debug mode, one request at a time
radtest -t tls user password 127.0.0.1 0 testing123
eapol_test -c /etc/wpa_supplicant/wpa_supplicant-TLS.conf -a 192.168.0.181 -s cisco123

! From the switch to the server
test aaa group dot1x-auth user password legacy

radiusd -X is the single most useful tool in this whole build. It prints the
handshake step by step, so a certificate validation failure is visible immediately instead of
appearing as a generic port rejection.

Common Failures

  • Port flaps between AUTHORIZED and UNAUTHORIZED — usually a certificate
    validity or EKU problem. Client certificates used for 802.1X need client authentication
    extended key usage.
  • No RADIUS response — the switch is missing from clients.conf,
    the shared secret differs, UDP 1812 is blocked, or the RADIUS packets leave from an unexpected
    source interface.
  • Handshake dies mid-flight — missing ok = return /
    updated = return in the eap section, or an MTU problem on the path.
  • Works on Wi-Fi, fails on wired — different supplicant policy. Windows
    requires the Wired AutoConfig service to be running and set to Automatic, plus a GPO
    or local policy for Wired Network (IEEE 802.3) Policies.

This is the server side of the story; the wireless and switch-side counterparts are covered
in WPA3 Enterprise, 802.1X and RADIUS configuration, IEEE 802.1X port-based authentication on access switches and ArubaOS-CX 802.1X port access with RADIUS and MAB roles.

原文链接:https://blog.avidpontoon.co.uk/cisco-freeradius-eap-tls-wired-802-1x/