170
# Specify the primary authentication server and primary accounting server, and configure the keys for
communication with the servers.
[RouterA-radius-rs1] primary authentication 192.168.0.111
[RouterA-radius-rs1] primary accounting 192.168.0.111
[RouterA-radius-rs1] key accounting radius
[RouterA-radius-rs1] key authentication radius
# Configure the router to not carry the ISP domain name in the username sent to the RADIUS server.
[RouterA-radius-rs1] user-name-format without-domain
# Specify the source IP address for outgoing RADIUS packets as 3.3.0.3.
[RouterA-radius-rs1] nas-ip 3.3.0.3
[RouterA-radius-rs1] quit
IMPORTANT:
Use
nas-ip
to specify the source IP address for outgoing RADIUS packets, and make sure that the
source IP address is consistent with the IP address of the access device specified on the server to avoid
authentication failures.
2.
Configure an authentication domain.
# Create an ISP domain named
dm1
and enter its view.
[RouterA] domain dm1
# Configure AAA methods for the ISP domain.
[RouterA-isp-dm1] authentication portal radius-scheme rs1
[RouterA-isp-dm1] authorization portal radius-scheme rs1
[RouterA-isp-dm1] accounting portal radius-scheme rs1
[RouterA-isp-dm1] quit
# Configure
dm1
as the default ISP domain for all users. Then, if a user enters a username without any
ISP domain at logon, the authentication and accounting methods of the default domain are used for the
user.
[RouterA] domain default enable dm1
3.
Configure portal authentication.
# Configure the portal server as follows:
•
Name: newpt
•
IP address: 192.168.0.111
•
VPN: vpn3
•
Key: portal
•
Port number: 50100
•
URL: http://192.168.0.111:8080/portal.
[RouterA] portal server newpt ip 192.168.0.111 vpn-instance vpn3 key portal port 50100
url http://192.168.0.111:8080/portal