beautypg.com

H3C Technologies H3C S6300 Series Switches User Manual

Page 145

background image

130

# Specify the security policy server.

[SwitchA-radius-rs1] security-policy-server 192.168.0.113

[SwitchA-radius-rs1] quit

# Enable RADIUS session control.

[SwitchA] radius session-control enable

2.

Configure an authentication domain:
# Create an ISP domain named dm1 and enter its view.

[SwitchA] domain dm1

# Configure AAA methods for the ISP domain.

[SwitchA-isp-dm1] authentication portal radius-scheme rs1

[SwitchA-isp-dm1] authorization portal radius-scheme rs1

[SwitchA-isp-dm1] accounting portal radius-scheme rs1

[SwitchA-isp-dm1] quit

# Configure domain dm1 as the default ISP domain. If a user enters the username without the ISP
domain name at login, the authentication and accounting methods of the default domain are used

for the user.

[SwitchA] domain default enable dm1

3.

Configure ACL 3000 as the isolation ACL and ACL 3001 as the security ACL:

[SwitchA] acl number 3000

[SwitchA-acl-adv-3000] rule permit ip destination 192.168.0.0 0.0.0.255

[SwitchA-acl-adv-3000] rule deny ip

[SwitchA-acl-adv-3000] quit

[SwitchA] acl number 3001

[SwitchA-acl-adv-3001] rule permit ip

[SwitchA-acl-adv-3001] quit

NOTE:

Make sure you specify ACL 3000 as the isolation ACL and ACL 3001 as the security ACL on the
security policy server.

4.

Configure portal authentication:
# Configure a portal authentication server.

[SwitchA] portal server newpt

[SwitchA-portal-server-newpt] ip 192.168.0.111 key simple portal

[SwitchA-portal-server-newpt] port 50100

[SwitchA-portal-server-newpt] quit

# Configure a portal Web server.

[SwitchA] portal web-server newpt

[SwitchA-portal-websvr-newpt] url http://192.168.0.111:8080/portal

[SwitchA-portal-websvr-newpt] quit

# Enable cross-subnet portal authentication on VLAN-interface 4.

[SwitchA] interface vlan-interface 4

[SwitchA–Vlan-interface4] portal enable method layer3

# Reference the portal Web server newpt on VLAN-interface 4.

[SwitchA–Vlan-interface4] portal apply web-server newpt