HP 10500 Series Configuration Manual page 69

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

[Switch-radius-rs1] server-type extended
# Specify the primary authentication server and primary accounting server, and configure the
keys for communication with the servers.
[Switch-radius-rs1] primary authentication 10.1.1.1
[Switch-radius-rs1] primary accounting 10.1.1.1
[Switch-radius-rs1] key authentication expert
[Switch-radius-rs1] key accounting expert
# Include the domain names in usernames sent to the RADIUS server.
[Switch-radius-rs1] user-name-format with-domain
[Switch-radius-rs1] quit
Configure an authentication domain:
b.
# Create an ISP domain named dm1 and enter its view.
[Switch] domain dm1
# Configure the ISP domain to use RADIUS scheme rs1.
[Switch-isp-dm1] authentication portal radius-scheme rs1
[Switch-isp-dm1] authorization portal radius-scheme rs1
[Switch-isp-dm1] accounting portal radius-scheme rs1
[Switch-isp-dm1] quit
# Configure dm1 as the default ISP domain for all users. Then, if a user enters a username
without any ISP domain at login, the authentication and accounting methods of the default
domain are used for the user.
[Switch] domain default enable dm1
c.
Configure portal authentication:
# Configure the portal server.
[Switch] portal server newpt ip 10.1.1.1 key portal port 50100 url
http://10.1.1.1:8080/portal
# Enable portal authentication on the interface connecting the host.
[Switch] interface vlan-interface 2
[Switch-Vlan-interface2] portal server newpt method direct
[Switch-Vlan-interface2] quit
5.
Verify the configuration:
The user can initiate portal authentication by using the HP iNode client or by accessing a
Webpage. All the initiated Web requests are redirected to the portal authentication page at
http://10.1.1.1:8080/portal. Before passing portal authentication, the user can access only the
authentication page. After passing portal authentication, the user can access the Internet.
After the user passes the portal authentication, use the following command to view the portal user
information on the switch.
[Switch] display portal user interface vlan-interface 2
Index:19
State:ONLINE
SubState:NONE
ACL:NONE
Work-mode:stand-alone
MAC
---------------------------------------------------------------------
0015-e9a6-7cfe
IP
Vlan
192.168.1.58
2
59
Interface
Vlan-interface2

Advertisement

Table of Contents
loading

Table of Contents