Specifying The Nas-Port-Id For An Interface; Specifying A Nas Id Profile For An Interface - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

a wireless client using portal authentication, the access port type obtained by the BAS may be the type
of the wired port that authenticates the user. To make sure the BAS delivers the right access port
information to the RADIUS server, specify the NAS-Port-Type according to the practical access
environment.
To specify the NAS-Port-Type value for an interface:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Specify the NAS-Port-Type
value for the interface.

Specifying the NAS-Port-ID for an interface

If the device uses a RADIUS server for authentication, authorization, and accounting of portal users,
when a portal user logs on from an interface, the device sends a RADIUS request that carries the
NAS-Port-ID attribute to the RADIUS server. The portal server configuration determines the usage of the
NAS-Port-ID attribute.
To specify the NAS-Port-ID value carried in a RADIUS request sent from an interface:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Configure the NAS-Port-ID
value.

Specifying a NAS ID profile for an interface

In some networks, user access points are identified by their access VLANs. Network carriers use
NAS-identifiers to identify user access points. With the NAS ID profile specified on an interface, when a
user logs in from the interface, the access device checks the specified profile to obtain the NAS ID that
is bound with the access VLAN. The value of this NAS ID is used as that of the NAS-identifier attribute
in the RADIUS packets to be sent to the RADIUS server.
The NAS ID profile defines the binding relationship between VLANs and NAS IDs. A NAS ID-VLAN
binding is defined by the nas-id id-value bind vlan vlan-id command, which is described in detail in AAA
configuration commands in the Security Command Reference.
If no NAS-ID profile is specified for an interface or no matching binding is found in the specified profile,
the device uses the device name as the interface NAS ID.
Command
system-view
interface interface-type
interface-number
portal nas-port-type { ethernet |
wireless }
Command
system-view
interface interface-type
interface-number
portal nas-port-id nas-port-id-value
137
Remarks
N/A
N/A
Not configured by default.
Remarks
N/A
N/A
By default, no NAS-Port-ID value is
specified for an interface, and the
switch uses the information
obtained from the physical
interface where the portal user
accesses as the NAS-Port-ID value
in a RADIUS request.

Advertisement

Table of Contents
loading

Table of Contents