Aaa For Portal Users By A Radius Server - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

[Switch] user-interface vty 0 15
[Switch-ui-vty0-15] authentication-mode scheme
# Configure the user interfaces to support SSH.
[Switch-ui-vty0-15] protocol inbound ssh
[Switch-ui-vty0-15] quit
# Create RADIUS scheme rad.
[Switch] radius scheme rad
# Specify the primary authentication server.
[Switch-radius-rad] primary authentication 10.1.1.1 1812
# Set the shared key for secure authentication communication to expert.
[Switch-radius-rad] key authentication expert
# Include the domain names in usernames sent to the RADIUS server.
[Switch-radius-rad] user-name-format with-domain
# Specify the service type for the RADIUS server, which must be extended when the RADIUS server
runs on IMC.
[Switch-radius-rad] server-type extended
[Switch-radius-rad] quit
# Configure the AAA methods for the domain.
[Switch] domain bbb
[Switch-isp-bbb] authentication login radius-scheme rad
[Switch-isp-bbb] authorization login radius-scheme rad
[Switch-isp-bbb] quit
3.
Verify the configuration:
After you complete the configuration, the SSH user should be able to use the configured account
to access the user interface of the switch and can access the demands of level 0 through level 3.
# Use the display connection command to view the connection information on the switch.
[Switch] display connection
Index=1
IP=192.168.1.58
IPv6=N/A
Total 1 connection(s) matched.

AAA for portal users by a RADIUS server

Network requirements
As shown in
Configure the switch to:
Use the RADIUS server for authentication, authorization, and accounting of portal users.
Provide direct portal authentication so that the host can access only the portal server before passing
portal authentication and can access the Internet after passing portal authentication.
Include the domain name in a username sent to the RADIUS server.
On the RADIUS server, add a service that charges 120 dollars for up to 120 hours per month, and
configure a user, and register the service for the user.
,Username=hello@bbb
Figure
15, the host automatically obtains a public network IP address through DHCP.
52

Advertisement

Table of Contents
loading

Table of Contents