
!
! No configuration change since last restart
!
version 12.2
no service pad
service timestamps debug datetime localtime
service timestamps log datetime localtime
service password-encryption
!
hostname nac-junico
!
enable secret 5 $1$He/E$0Hfay7ggY6cWfHd8O5EUW.
enable password 7 09424F0A170414425D
!
username nac privilege 15 password 7 06080E22424F0A4953
username jms privilege 15 password 7 011D0F100F5F080E22
username administrator privilege 15 password 7 121704141C0A0F547C
username root privilege 15 password 7 0505070C2F4D4D594F
username cisco privilege 15 password 7 1040081A0B16115B5A
aaa new-model
aaa authentication login default local
aaa authentication dot1x default group radius
aaa authorization exec default local if-authenticated 
aaa authorization network default group radius 
!
aaa session-id common
clock timezone PST -8
clock summer-time PST recurring
ip subnet-zero
ip domain-name nac.ilabs.interop.net
ip name-server 45.200.1.2
!
vtp mode transparent
!
no setup express
!
crypto pki trustpoint TP-self-signed-3188939264
 enrollment selfsigned
 subject-name cn=IOS-Self-Signed-Certificate-3188939264
 revocation-check none
 rsakeypair TP-self-signed-3188939264
!
!
crypto ca certificate chain TP-self-signed-3188939264
 certificate self-signed 01
  308202BB 30820224 A0030201 02020101 300D0609 2A864886 F70D0101 04050030 
  62312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274 
  69666963 6174652D 33313838 39333932 3634312F 302D0609 2A864886 F70D0109 
  0216206E 61632D6A 756E6963 6F2E6E61 632E696C 6162732E 696E7465 726F702E 
  6E657430 1E170D39 33303330 31303030 3131375A 170D3230 30313031 30303030 
  30305A30 62312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 
  43657274 69666963 6174652D 33313838 39333932 3634312F 302D0609 2A864886 
  F70D0109 0216206E 61632D6A 756E6963 6F2E6E61 632E696C 6162732E 696E7465 
  726F702E 6E657430 819F300D 06092A86 4886F70D 01010105 0003818D 00308189 
  02818100 B9FDC664 1BD1FA9D 6FDA8B5F 4E313C62 2A5B7090 48AF94F6 9DAB2A0F 
  6848A8C5 1B63BD31 AAB5A86A A082D295 28907EFF 8B27740A 43C6AF87 1745325D 
  B4439EB0 2E275836 3F26B68D 43FC3112 F2E7CEF8 37767FFA 9C90909B E681B71B 
  5A037A6B 7A98EBED 7106B30C FDB998C9 AE642187 7C3B25E3 90A99F2E 2FA7FCE2 
  0A5E56E9 02030100 01A38180 307E300F 0603551D 130101FF 04053003 0101FF30 
  2B060355 1D110424 30228220 6E61632D 6A756E69 636F2E6E 61632E69 6C616273 
  2E696E74 65726F70 2E6E6574 301F0603 551D2304 18301680 14B9E2ED C876ADD1 
  4C5F63AE 3DD2C413 DB262D9F B1301D06 03551D0E 04160414 B9E2EDC8 76ADD14C 
  5F63AE3D D2C413DB 262D9FB1 300D0609 2A864886 F70D0101 04050003 81810043 
  4BE403E7 E342E723 BAC137F8 D7B29EAE 77566054 08BF9CA7 F5F5ABCC 6ACEDB01 
  A0CD8916 FAD33E2B 773F1E4D 5063A2EB 65549BC7 F180355B B95B1067 0BBCED9E 
  5836EDB4 D08F3DFA 9D249CF4 495639A1 3C932E64 F744F500 6EBA2A24 F0473766 
  BDE9AAFE E46F2C34 325FA4BF CE35A46D D663B054 833EBC16 DFF639D8 2DA258
  quit
!
!
dot1x system-auth-control
no file verify auto
!
spanning-tree mode pvst
spanning-tree extend system-id
no spanning-tree vlan 1-1000
!
vlan internal allocation policy ascending
vlan dot1q tag native 
!
vlan 30
 name TCG30
!
vlan 31
 name TCG31
!
vlan 32
 name TCG32
!
vlan 33 
!
vlan 500
 name Management
!
vlan 516
 name Servers
!
vlan 564
 name Wired
!
vlan 628
 name Wireless
!
vlan 1000
 name Backbone
!
!
interface FastEthernet0/1
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/2
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/3
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/4
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/5
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/6
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/7
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/8
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/9
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/10
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/11
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/12
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/13
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/14
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/15
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/16
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/17
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/18
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/19
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/20
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/21
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/22
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/23
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/24
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/25
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/26
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/27
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/28
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/29
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/30
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/31
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/32
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/33
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/34
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/35
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/36
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/37
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/38
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/39
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/40
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/41
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/42
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/43
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/44
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/45
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/46
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
 dot1x timeout reauth-period 300
 dot1x reauthentication
 dot1x auth-fail vlan 31
 spanning-tree portfast
!
interface FastEthernet0/47
 description 802.1X Ports for Access
 switchport access vlan 32
 switchport mode access
 spanning-tree portfast
!
interface FastEthernet0/48
 description Uplink to Juniper to Core
 switchport access vlan 32
 switchport mode access
!
interface GigabitEthernet0/1
 switchport mode dynamic desirable
!
interface GigabitEthernet0/2
 switchport mode dynamic desirable
!
interface Vlan1
 no ip address
 shutdown
!
interface Vlan32
 description Management for Switch
 ip address 45.200.32.61 255.255.255.0
!
ip default-gateway 45.200.32.1
ip classless
ip http server
ip http secure-server
!
!
logging 45.200.1.2
radius-server host 45.200.1.55 auth-port 1645 acct-port 1646 key 7 0505070C2F4D4D594F
radius-server source-ports 1645-1646
!
control-plane
!
!
line con 0
line vty 0 4
 transport input telnet ssh
 escape-character 3
line vty 5 15
!
ntp clock-period 17180450
ntp server 45.200.1.2 prefer
end
