Configuring Re-Dhcp Portal Authentication - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

# Configure domain dm1 as the default ISP domain for all users. Then, if a user enters the
username without the ISP domain at logon, the authentication and accounting methods of the
default domain are used for the user.
[Switch] domain default enable dm1
3.
Configure portal authentication:
# Configure a portal server on the switch, specifying the portal server name as newpt, IP address
as 192.168.0.111, key as plaintext string portal, port number as 50100, and URL as
http://192.168.0.111:8080/portal.
[Switch] portal server newpt ip 192.168.0.111 key simple portal port 50100 url
http://192.168.0.111:8080/portal
# Enable portal authentication on the interface connecting the host.
[Switch] interface vlan-interface 100
[Switch–Vlan-interface100] portal server newpt method direct
[Switch–Vlan-interface100] quit

Configuring re-DHCP portal authentication

Network requirements
As shown in
The host is directly connected to the switch and the switch is configured for re-DHCP authentication.
The host is assigned with an IP address through the DHCP server. Before passing portal
authentication, the host uses an assigned private IP address. After passing portal authentication, it
can get a public IP address and then users can access Internet resources.
A RADIUS server serves as the authentication/accounting server.
Figure 61 Network diagram
Host
automatically obtains
an IP address
Configuration procedure
When you configure re-DHCP portal authentication, follow these guidelines:
Configure a public address pool (20.20.20.0/24, in this example) and a private address pool
(10.0.0.0/24, in this example) on the DHCP server. (Details not shown.)
The switch must be configured as a DHCP relay agent and the portal-enabled interface must be
configured with a primary IP address (a public IP address) and a secondary IP address (a private
Figure
61:
Vlan-int100
20.20.20.1/24
10.0.0.1/24 sub
Switch
Vlan-int2
192.168.0.100/24
147
Portal server
192.168.0.111/24
DHCP server
192.168.0.112/24
RADIUS server
192.168.0.113/24

Advertisement

Table of Contents
loading

Table of Contents