Aaa For Portal Users By A Radius Server - H3C S5500-EI Series Security Configuration Manual

Hide thumbs Also See for S5500-EI Series:
Table of Contents

Advertisement

[Switch] radius scheme rad
# Specify the primary authentication server.
[Switch-radius-rad] primary authentication 10.1.1.1 1812
# Set the shared key for secure authentication communication to expert.
[Switch-radius-rad] key authentication expert
# Configure the scheme to include the domain names in usernames to be sent to the RADIUS server.
[Switch-radius-rad] user-name-format with-domain
# Specify the service type for the RADIUS server, which must be extended when the RADIUS server runs
on CAMS or IMC.
[Switch-radius-rad] server-type extended
[Switch-radius-rad] quit
# Configure the AAA methods for the domain.
[Switch] domain bbb
[Switch-isp-bbb] authentication login radius-scheme rad
[Switch-isp-bbb] authorization login radius-scheme rad
[Switch-isp-bbb] quit
Verifying the configuration
After you complete the configuration, the SSH user should be able to use the configured account to
access the user interface of the switch and can access the demands of level 0 through level 3. .
# Use the display connection command to view the connection information on the switch.
[Switch] display connection
Index=1
IP=192.168.1.58
IPv6=N/A
Total 1 connection(s) matched.

AAA for portal users by a RADIUS server

Network requirements
As shown in
Configure the switch to:
Use the RADIUS server for authentication, authorization, and accounting of portal users.
Provide direct portal authentication so that the host can access only the portal server before passing
portal authentication and can access the Internet after passing portal authentication.
Keep the domain names in usernames sent to the RADIUS server.
On the RADIUS server, add a service that charges 120 dollars for up to 120 hours per month, create an
account for portal users, and assign the service to the account.
Set the shared keys for secure RADIUS communication to expert. Set the ports for
authentication/authorization and accounting to 1812 and 1813, respectively.
,Username=hello@bbb
Figure
16, the host automatically obtains a public network IP address through DHCP.
56

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5500-si series

Table of Contents