beautypg.com

H3C Technologies H3C S6300 Series Switches User Manual

Page 132

background image

117

system-view

[Switch] radius scheme rs1

# Specify the primary authentication server and primary accounting server, and configure the keys

for communication with the servers.

[Switch-radius-rs1] primary authentication 192.168.0.113

[Switch-radius-rs1] primary accounting 192.168.0.113

[Switch-radius-rs1] key authentication simple radius

[Switch-radius-rs1] key accounting simple radius

# Exclude the ISP domain name from the username sent to the RADIUS server.

[Switch-radius-rs1] user-name-format without-domain

[Switch-radius-rs1] quit

# Enable RADIUS session control.

[Switch] radius session-control enable

2.

Configure an authentication domain:
# Create an ISP domain named dm1 and enter its view.

[Switch] domain dm1

# Configure AAA methods for the ISP domain.

[Switch-isp-dm1] authentication portal radius-scheme rs1

[Switch-isp-dm1] authorization portal radius-scheme rs1

[Switch-isp-dm1] accounting portal radius-scheme rs1

[Switch-isp-dm1] quit

# Configure domain dm1 as the default ISP domain. If a user enters the username without the ISP

domain name at login, the authentication and accounting methods of the default domain are used

for the user.

[Switch] domain default enable dm1

3.

Configure DHCP relay and authorized ARP:
# Configure DHCP relay.

[Switch] dhcp enable

[Switch] dhcp relay client-information record

[Switch] interface vlan-interface 100

[Switch–Vlan-interface100] ip address 20.20.20.1 255.255.255.0

[Switch–Vlan-interface100] ip address 10.0.0.1 255.255.255.0 sub

[Switch-Vlan-interface100] dhcp select relay

[Switch-Vlan-interface100] dhcp relay server-address 192.168.0.112

# Enable authorized ARP.

[Switch-Vlan-interface100] arp authorized enable

[Switch-Vlan-interface100] quit

4.

Configure portal authentication:
# Configure a portal authentication server.

[Switch] portal server newpt

[Switch-portal-server-newpt] ip 192.168.0.111 key simple portal

[Switch-portal-server-newpt] port 50100

[Switch-portal-server-newpt] quit

# Configure a portal Web server.

[Switch] portal web-server newpt

[Switch-portal-websvr-newpt] url http://192.168.0.111:8080/portal