HP 3600 v2 Series Security Configuration Manual page 132

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

Configure the ACL assignment.
1.
# Configure ACL 3000 to deny packets destined for 10.0.0.1.
<Sysname> system-view
[Sysname] acl number 3000
[Sysname-acl-adv-3000] rule 0 deny ip destination 10.0.0.1 0
[Sysname-acl-adv-3000] quit
Configure RADIUS-based MAC authentication on the device.
2.
# Configure a RADIUS scheme.
[Sysname] radius scheme 2000
[Sysname-radius-2000] primary authentication 10.1.1.1 1812
[Sysname-radius-2000] primary accounting 10.1.1.2 1813
[Sysname-radius-2000] key authentication abc
[Sysname-radius-2000] key accounting abc
[Sysname-radius-2000] user-name-format without-domain
[Sysname-radius-2000] quit
# Apply the RADIUS scheme to an ISP domain for authentication, authorization, and accounting.
[Sysname] domain 2000
[Sysname-isp-2000] authentication default radius-scheme 2000
[Sysname-isp-2000] authorization default radius-scheme 2000
[Sysname-isp-2000] accounting default radius-scheme 2000
[Sysname-isp-2000] quit
# Enable MAC authentication globally.
[Sysname] mac-authentication
# Specify the ISP domain for MAC authentication.
[Sysname] mac-authentication domain 2000
# Configure the device to use MAC-based user accounts, and the MAC addresses are hyphen separated
and in lowercase.
[Sysname] mac-authentication user-name-format mac-address with-hyphen lowercase
# Enable MAC authentication for port Ethernet 1/0/1.
[Sysname] interface ethernet 1/0/1
[Sysname-Ethernet1/0/1] mac-authentication
Configure the RADIUS servers.
3.
# Add a user account with 00-e0-fc-12-34-56 as both the username and password on the RADIUS server,
and specify ACL 3000 as the authorization ACL for the user account. (Details not shown)
Verifying the configuration
After the host passes authentication, perform the display connection command on the device to view
online user information.
[Sysname-Ethernet1/0/1] display connection
Slot:
1
Index=9
IP=N/A
IPv6=N/A
MAC=00e0-fc12-3456
, Username=00-e0-fc-12-34-56@2000
121

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

A3100-48 v2

Table of Contents