HPE FlexNetwork 10500 Series Security Configuration Manual page 248

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuration procedure
Perform the following tasks on the switch.
1.
Configure a preauthentication IP address pool:
# Configure DHCP address pool pre to assign IP addresses and other configuration
parameters to clients on subnet 2.2.2.0/24.
<Switch> system-view
[Switch] dhcp server ip-pool pre
[Switch-dhcp-pool-pre] gateway-list 2.2.2.1
[Switch-dhcp-pool-pre] network 2.2.2.0 24
[Switch-dhcp-pool-pre] quit
# Enable the DHCP server on VLAN-interface 100.
[Switch] interface vlan-interface 100
[Switch–Vlan-interface100] dhcp select server
[Switch–Vlan-interface100] quit
2.
Configure a preauthentication domain:
# Create an ISP domain named abc and enter its view.
[Switch] domain abc
# Specify authorization ACL 3010 in the domain.
[Switch-isp-abc] authorization-attribute acl 3010
[Switch-isp-abc] quit
# Configure a rule to permit access to the subnet 192.168.0.0/24.
[Switch] acl advanced 3010
[Switch-acl-ipv4-adv-3010] rule 1 permit ip destination 192.168.0.0 24
[Switch-acl-ipv4-adv-3010] quit
# Configure preauthentication domain abc on VLAN-interface 100.
[Switch] interface vlan-interface 100
[Switch–Vlan-interface100] portal pre-auth domain abc
[Switch–Vlan-interface100] quit
3.
Configure portal authentication:
# Configure a portal authentication server.
[Switch] portal server newpt
[Switch-portal-server-newpt] ip 192.168.0.111 key simple portal
[Switch-portal-server-newpt] port 50100
[Switch-portal-server-newpt] quit
# Configure a portal Web server.
[Switch] portal web-server newpt
[Switch-portal-websvr-newpt] url http://192.168.0.111:8080/portal
[Switch-portal-websvr-newpt] quit
# Enable direct portal authentication on VLAN-interface 100.
[Switch] interface vlan-interface 100
[Switch–Vlan-interface100] portal enable method direct
# Specify portal Web server newpt on VLAN-interface 100.
[Switch–Vlan-interface100] portal apply web-server newpt
# Configure the BAS-IP as 2.2.2.1 for portal packets sent from VLAN-interface 100 to the portal
authentication server.
[Switch–Vlan-interface100] portal bas-ip 2.2.2.1
[Switch–Vlan-interface100] quit
231

Advertisement

Table of Contents
loading

Table of Contents