Configuring Cross-Subnet Portal Authentication For Mpls L3Vpns - HP MSR Series Configuration Manual

Hpe flexnetwork msr router series
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

[Router–GigabitEthernet2/0/2] portal enable method direct
# Enable portal fail-permit for the portal authentication server newpt.
[Router–GigabitEthernet2/0/2] portal fail-permit server newpt
# Reference the portal Web server newpt on GigabitEthernet 2/0/2.
[Router–GigabitEthernet2/0/2] portal apply web-server newpt
# Configure the BAS-IP as 2.2.2.1 for portal packets sent from GigabitEthernet 2/0/2 to the
portal authentication server.
[Router–GigabitEthernet2/0/2] portal bas-ip 2.2.2.1
[Router–GigabitEthernet2/0/2] quit
Verifying the configuration
# Use the following command to display information about the portal authentication server.
[Router] display portal server newpt
Portal server: newpt
IP
VPN instance
Port
Server Detection
User synchronization
Status
The Up status of the portal authentication server indicates that the portal authentication server is
reachable. If the access device detects that the portal authentication server is unreachable, the
Status field in the command output displays Down. The access device generates a server
unreachable log "Portal server newpt turns down from up." and disables portal authentication on the
access interface, so the host can access the external network without authentication.
Configuring cross-subnet portal authentication for MPLS
L3VPNs
Network requirements
As shown in
A portal server in VPN 3 acts as the portal authentication server, portal Web server, and RADIUS
server.
Configure cross-subnet portal authentication on Router A, so the host can access Internet resources
after passing identity authentication.
Figure 78 Network diagram
Configuration prerequisites
Before enabling portal authentication, configure MPLS L3VPN and specify VPN targets for VPN
1 and VPN 3 so that VPN 1 and VPN 3 can communicate with each other. This example
: 192.168.0.111
: Not configured
: 50100
: Timeout 40s
: Timeout 600s
: Up
Figure
78, the PE device Router A provides portal authentication for the host in VPN 1.
Action: log
192

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents