Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

The following example shows how to authenticate the dot1x users by a RADIUS server. The management IP address is 10.100.5.33/24.

  1. Assign an IP address to 1/0/19, and set force authorized mode to this port, and create a user name list dot1xList.

    (Netgear Switch) #config
    (Netgear Switch) (Config)#ip routing
    (Netgear Switch) (Config)#interface 1/0/1
    (Netgear Switch) (Interface 1/0/1)#routing
    (Netgear Switch) (Interface 1/0/1)#ip address 192.168.1.1 255.255.255.0
    (Netgear Switch) (Config)#dot1x system-auth-control
    (Netgear Switch) (Config)#interface 1/0/19
    (Netgear Switch) (Interface 1/0/19)#routing
    (Netgear Switch) (Interface 1/0/19)#ip address 10.100.5.33 255.255.255.0
    (Netgear Switch) (Interface 1/0/19)#dot1x port-control force-authorized

     
  2. Use RADIUS to authenticate the dot1x users.

    (Netgear Switch) (Config)#aaa authentication dot1x default radius
     
  3. Configure a RADIUS authentication server.

    (Netgear Switch) (Config)#radius server host auth 10.100.5.17
     
  4. Configure the shared secret between the RADIUS client and the server.

    (Netgear Switch) (Config)#radius server key auth 10.100.5.17
    Enter secret (16 characters max):123456
    Re-enter secret:123456

     
  5. Set the RADIUS server as a primary server.

    (Netgear Switch) (Config)#radius server msgauth 10.100.5.17
    (Netgear Switch) (Config)# radius server primary 10.100.5.17

     
  6. Configure an accounting server.

    (Netgear Switch) (Config)#radius accounting mode
    (Netgear Switch) (Config)#radius server host acct 10.100.5.17

     
  7. Configure the shared secret between the accounting server and the client.

    (Netgear Switch) (Config)#radius server key acct 10.100.5.17
    Enter secret (16 characters max):123456
    Re-enter secret:123456


For more information, see the following support articles:

 

 

This article applies to the following managed switches and their respective firmware:

 

 

  • M5300 - firmware version 10.0.0.x
    • M5300-28G (GSM7228S)
    • M5300-5G (GSM7252S)
    • M5300-28G3 (GSM7328Sv2h2)
    • M5300-52G3 (GSM7352Sv2h2)
    • M5300-28G_POE+ (GSM7228PSv1h2)
    • M5300-52G-POE+ (GSM7252PSv1h2)
    • M5300-28GF3 (GSM7328FSv2)
  • M4100 - firmware version 10.0.1.x
    • M4100-26G (GSM7224v2h2)
    • M4100-50G (GSM7248v2h2)
    • M4100-26G-POE (GSM7226Pv1h1)
    • M4100-50G-POE+ (GSM7248Pv1h1)
    • M4100-26G-POE (FSM7226Pv1h1)
    • M4100-50-POE (FSM7250Pv1h1)
    • M4100-D12G (GSM5212v1h1)
    • M4100-D10-POE (FSM5210Pv1h1)
  • M7100 - firmware version 10.0.1.x
    • M7100-24X (XSM7224)
  • XSM7224S - firmware version 9.0.1.x
Last Updated:07/07/2025 | Article ID: 21797

Our team is here to help!

Phone
Chat
Email