1-18
Figure 1-11
Configure Layer 3 portal authentication
Switch A
Host
Vlan-int4
20.20.20.1/24
Portal server
192.168.0.111/24
RADIUS server
192.168.0.112/24
Vlan-int2
192.168.0.100/24
Switch B
Vlan-int4
20.20.20.2/24
Vlan-int2
8.8.8.1/24
8.8.8.2/24
Configuration procedure
z
You need to configure IP addresses for the devices as shown in
Figure 1-11
and ensure that routes
are available between devices.
z
Perform configurations on the RADIUS server to ensure that the user authentication and
accounting functions can work normally.
Configure Switch A:
1) Configure a RADIUS scheme
# Create a RADIUS scheme named
rs1
and enter its view.
<SwitchA> system-view
[SwitchA] radius scheme rs1
# Set the server type for the RADIUS scheme. When using the iMC server, you need set the server type
to
extended
.
[SwitchA-radius-rs1] server-type extended
# Specify the primary authentication server and primary accounting server, and configure the keys for
communication with the servers.
[SwitchA-radius-rs1] primary authentication 192.168.0.112
[SwitchA-radius-rs1] primary accounting 192.168.0.112
[SwitchA-radius-rs1] key authentication radius
[SwitchA-radius-rs1] key accounting radius
# Specify that the ISP domain name should not be included in the username sent to the RADIUS server.
[SwitchA-radius-rs1] user-name-format without-domain
[SwitchA-radius-rs1] quit
2) Configure an authentication domain
# Create an ISP domain named dm1 and enter its view.
[SwitchA] domain dm1