Configuring Extended Cross-Subnet Portal Authentication - HP 5920 Series Configuration Manual

Hide thumbs Also See for 5920 Series:
Table of Contents

Advertisement

Destination authenticate subnet:
IP address
IPv6:
Portal status: Disabled
Authentication type: Disabled
Portal Web server: Not configured
Authentication domain: Not configured
Bas-ipv6: Not configured
User detection: Not configured
Action for server detection:
Server type
--
Layer3 source network:
IP address
Destination authenticate subnet:
IP address
Before a user performs portal authentication by using the HP iNode client, the user can access only the
authentication page http://192.168.0.1 1 1:8080/portal. All Web requests the user initiates will be
redirected to the authentication page. If the user passes the authentication but fails the security check, the
user can access only the resources that match ACL 3000. After passing both the authentication and the
security check, the user can access Internet resources that match ACL 3001.
After the user passes authentication, you can use the following command to display information about
the portal user.
[Switch] display portal user interface vlan-interface 100
Total portal users: 1
Username: abc
Portal server: newpt
State: Online
Authorization ACL: 3001
VPN instance: --
MAC
0015-e9a6-7cfe

Configuring extended cross-subnet portal authentication

Network requirements
As shown in
Switch B. A portal server serves as both a portal authentication server and a portal Web server. A
RADIUS server serves as the authentication/accounting server.
Configure Switch A for extended cross-subnet portal authentication. Before passing portal authentication,
the host can access only the portal server. After passing portal identity authentication, the host accepts
security check. If the host fails the security check it can access only the subnet 192.168.0.0/24. After
passing the security check, the host can access Internet resources.
Server name
--
IP
20.20.20.2
Figure
52, Switch A supports portal authentication. The host accesses Switch A through
Mask
VLAN
Interface
100
Vlan-interface100
128
Action
--
Prefix length
Prefix length

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents