Cross-Subnet Portal Authentication Across Vpns - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

The Up state of the portal server indicates that the portal server is reachable. If the access device detects
that the portal server is unreachable, you can see the portal server status is Down in the output, and the
access device generates a server unreachable trap "portal server newpt lost" and disables portal
authentication on the access interface, so the client can access the external network without
authentication.

Cross-subnet portal authentication across VPNs

Network requirements
As shown in
authentication for hosts in VPN 1. The RADIUS server/portal server is in VPN 3.
Figure 56 Network diagram
Configuration prerequisites and guidelines
Before enabling portal authentication, be sure to configure the MPLS L3VPN capabilities properly
and specify VPN targets for VPN 1 and VPN 3 so that VPN 1 and VPN 3 can communicate with
each other. This example gives only the access authentication configuration on the user-side PE. For
information about MPLS L3VPN, see MPLS Configuration Guide.
Configure the RADIUS server properly to provide normal authentication/accounting functions for
users.
Configuration procedure
Configure a RADIUS scheme:
1.
# Create a RADIUS scheme named rs1 and enter its view.
<SwitchA> system-view
[SwitchA] radius scheme rs1
# Configure the VPN instance to which the RADIUS scheme belongs as vpn3.
[SwitchA-radius-rs1] vpn-instance vpn3
# Set the server type for the RADIUS scheme. When using the IMC server, you must set the server
type to extended.
[SwitchA-radius-rs1] server-type extended
# Specify the primary authentication server and primary accounting server, and configure the keys
for communication with the servers.
[SwitchA-radius-rs1] primary authentication 192.168.0.111
[SwitchA-radius-rs1] primary accounting 192.168.0.111
[SwitchA-radius-rs1] key accounting simple radius
[SwitchA-radius-rs1] key authentication simple radius
# Configure the switch to not carry the ISP domain name in the username sent to the RADIUS
server.
Figure
56, Switch A, as the PE connecting the user side, needs to provide Layer 3 portal
141

Advertisement

Table of Contents
loading

Table of Contents