168
# Configure AAA methods for the ISP domain.
[Router-isp-dm1] authentication portal radius-scheme rs1
[Router-isp-dm1] authorization portal radius-scheme rs1
[Router-isp-dm1] accounting portal radius-scheme rs1
[Router-isp-dm1] quit
# Configure
dm1
as the default ISP domain for all users. Then, if a user enters a username without any
ISP domain at logon, the authentication and accounting methods of the default domain are used for the
user.
[Router] domain default enable dm1
•
Configure portal authentication.
# Configure the portal server as needed.
[Router] portal server newpt ip 192.168.0.111 key portal port 50100 url
http://192.168.0.111:8080/portal
# Enable portal authentication on the interface connecting the host.
[Router] interface gigabitethernet 1/0/2
[Router–Gigabitethernet1/0/2] portal server newpt method direct
[Router–Gigabitethernet1/0/2] quit
•
Configure the portal server detection function.
# Configure the access device to detect portal server
newpt
, specifying the detection method as portal
heartbeat probe, setting the server probe interval to 40 seconds. Also, specify the access device to send
a server unreachable trap message, and disable portal authentication to permit unauthenticated portal
users if two consecutive probes fail.
[Router] portal server newpt server-detect method portal-heartbeat action trap permit-all
interval 40 retry 2
NOTE:
The product of
interval
and
retry
must be greater than or equal to the portal server heartbeat interval.
HP recommends that you configure the
interval
to be greater than the portal server heartbeat interval
configured on the portal server.
•
Configure portal user information synchronization.
# Configure the access device to synchronize portal user information with portal server
newpt
, setting
the synchronization probe interval to 600 seconds and specifying the access device to log off users if
the users do not appear in the user synchronization packets sent from the server within two consecutive
probe intervals.
[Router] portal server newpt user-sync interval 600 retry 2
NOTE:
The product of
interval
and
retry
must be greater than or equal to the portal user heartbeat interval. HP
recommends that you configure the
interval
to be greater than the portal user heartbeat interval
configured on the portal server.