A. Test topology:
Reference Link: http://blog.sina.com.cn/s/blog_52ddfea30100gf4r.html
Http://www.cisco.com/en/US/docs/ios/sec_user_services/configuration/guide/sec_vpn_ac_802_1x.html
Two. Basic ideas:
A. Branch offices Configure Site-to-site VPN with headquarters and enable DHCP server and dot1x authentication
B.dhcp assign a different address pool based on whether or not to pass DOT1X authentication
C.vpn interest Stream masks the address of a DHCP address pool that has not been DOT1X certified
D. Thus realizing that only dot1x authenticated users can connect to the Headquarters intranet
---it is worth noting that the branch office connecting the router can not be a switch, only the hub, Cisco explained as follows:
Note
If There is a switch located between the router and the supplicant (client PC), the EAPOL frames won't reach the router Because the switch discards them.
A supplicant is A entity at one end of a point-to-point LAN segment this is being authenticated by a authenticator is attached to the "other" link.
---If you connect a router's switch, you can turn DHCP and dot1x on the switch, and assign a different address based on whether it is authenticated, the same way as the router