366
State: Online
VPN instance: vpn3
MAC IP VLAN Interface
0000-0000-0000 3.3.0.1 -- GigabitEthernet1/0/1
Authorization information:
DHCP IP pool: N/A
User profile: N/A
Session group profile: N/A
ACL: N/A
Inbound CAR: N/A
Outbound CAR: N/A
Inbound priority: N/A
Outbound priority: N/A
Example: Configuring direct portal authentication with a
preauthentication policy
Network configuration
As shown in
, the host is directly connected to the router (the access device). The host is
assigned a public IP address through DHCP. A portal server acts as both a portal authentication
server and a portal Web server. A RADIUS server acts as the authentication/accounting server.
Configure direct portal authentication, so the host can access only subnet 192.168.0.0/24 before
passing the authentication and access other network resources after passing the authentication.
Figure 127 Network diagram
Configuration prerequisites
•
Configure IP addresses for the host, router, and servers as shown in
and make sure
they can reach each other.
•
Configure the RADIUS server correctly to provide authentication and accounting functions.
Procedure
Perform the following tasks on the router.
1.
Configure a preauthentication IP address pool:
# Configure DHCP address pool
pre
to assign IP addresses and other configuration
parameters to clients on subnet 2.2.2.0/24.
<Router> system-view
[Router] dhcp server ip-pool pre
2.2.2.2/24
Gateway: 2.2.2.1/24
Router
Host
GE1/0/2
2.2.2.1/24
GE1/0/1
192.168.0.100/24
Portal server
192.168.0.111/24
RADIUS server
192.168.0.112/24