H3C LS-3100-52P-OVS-H3 Operation Manual page 1406

S5500-ei series ethernet switches
Table of Contents

Advertisement

passed security authentication, they can access only subnet 192.168.0.0/24. After passing security
authentication, they can access unrestricted Internet resources.
A RADIUS server serves as the authentication/accounting server.
Figure 1-7 Configure direct portal authentication with extended functions
Vlan-int100
2.2.2.1/24
Host
2.2.2.2/24
Gateway : 2.2.2.1/24
Configuration procedure
You need to configure IP addresses for the devices as shown in
available between devices.
Configure the switch:
1)
Configure a RADIUS scheme
# Create a RADIUS scheme named rs1 and enter its view.
<Switch> system-view
[Switch] radius scheme rs1
# Set the server type to extended.
[Switch-radius-rs1] server-type extended
# Specify the primary authentication server and primary accounting server, and configure the keys for
communication with the servers.
[Switch-radius-rs1] primary authentication 192.168.0.112
[Switch-radius-rs1] primary accounting 192.168.0.112
[Switch-radius-rs1] key accounting radius
[Switch-radius-rs1] key authentication radius
[Switch-radius-rs1] user-name-format without-domain
# Configure the IP address of the security policy server.
[Switch-radius-rs1] security-policy-server 192.168.0.113
[Switch-radius-rs1] quit
2)
Configure an authentication domain
Vlan-int2
192.168.0.100/24
Switch
1-17
Portal server
192.168.0.111/24
RADIUS server
192.168.0.112/24
Security policy server
192.168.0.113/24
Figure 1-7
and ensure that routes are

Advertisement

Chapters

Table of Contents
loading

Table of Contents