HP FlexNetwork 10500 Series Security Configuration Manual page 201

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

# Enable RADIUS session control.
[Switch] radius session-control enable
2.
Configure an authentication domain:
# Create an ISP domain named dm1 and enter its view.
[Switch] domain dm1
# Configure AAA methods for the ISP domain.
[Switch-isp-dm1] authentication portal radius-scheme rs1
[Switch-isp-dm1] authorization portal radius-scheme rs1
[Switch-isp-dm1] accounting portal radius-scheme rs1
[Switch-isp-dm1] quit
# Configure domain dm1 as the default ISP domain. If a user enters the username without the
ISP domain name at login, the authentication and accounting methods of the default domain
are used for the user.
[Switch] domain default enable dm1
3.
Configure portal authentication:
# Create a local portal Web server. Use HTTP to exchange authentication information with
clients.
[Switch] portal local-web-server http
# Specify file abc.zip as the default authentication page file for local portal authentication.
(Make sure the file exist under the root directory of the switch.)
[Switch–portal-local-websvr-http] default-logon-page abc.zip
# Set the HTTP service listening port number to 2331 for the local portal Web server.
[Switch–portal-local-webserver-http] tcp-port 2331
[Switch–portal-local-websvr-http] quit
# Configure the portal Web server name as newpt and URL as the IP address of the portal
authentication-enabled interface or a loopback interface (except 127.0.0.1).
[Switch] portal web-server newpt
[Switch-portal-websvr-newpt] url http://2.2.2.1:2331/portal
[Switch-portal-websvr-newpt] quit
# Enable direct portal authentication on VLAN-interface 100.
[Switch] interface vlan-interface 100
[Switch–Vlan-interface100] portal enable method direct
# Specify the portal Web server newpt on VLAN-interface 100.
[Switch–Vlan-interface100] portal apply web-server newpt
[Switch–Vlan-interface100] quit
Verifying the configuration
# Verify that the portal configuration has taken effect.
[Switch] display portal interface vlan-interface 100
Portal information of Vlan-interface 100
VSRP instance: --
VSRP state: N/A
Authorization
ACL
User profile
IPv4:
Portal status: Enabled
Authentication type: Direct
Portal web server: newpt
Strict checking
Disabled
Disabled
187

Advertisement

Table of Contents
loading

Table of Contents