ESR-Series. User manual
548
Then, create rules for redirecting to portal and passing traffic to the Internet:
esr(config)# ip access-list extended WELCOME
esr(config-acl)# rule
10
esr(config-acl-rule)# action permit
esr(config-acl-rule)# match protocol any
esr(config-acl-rule)# match source-address any
esr(config-acl-rule)# match destination-address any
esr(config-acl-rule)# enable
esr(config-acl-rule)# exit
esr(config-acl)# exit
esr (config)# ip access-list extended INTERNET
esr(config-acl)# rule
10
esr(config-acl-rule)# action permit
esr(config-acl-rule)# match protocol any
esr(config-acl-rule)# match source-address any
esr(config-acl-rule)# match destination-address any
esr(config-acl-rule)# enable
esr(config-acl-rule)# exit
esr(config-acl)# exit
Specify web resources which are available without authorization:
esr(config)# object-group url defaultservice
esr(config-object-group-url)# url http:
//eltex.nsk.ru
esr(config-object-group-url)# exit
The URL filtering lists are kept on SoftWLC server (you need to change only IP address of SoftWLC server, if
addressing is different from the example. Leave the rest of URL without changes):
esr(config)# subscriber-control filters-server-url http:
//192.0.2.20:7070/Filters/file/
Configure and enable BRAS, define NAS IP as address of the interface interacting with SoftWLC
(gigabitethernet 1/0/24 in the example):
esr(config)# subscriber-control
esr(config-subscriber-control)# aaa das-profile CoA
esr(config-subscriber-control)# aaa sessions-radius-profile RADIUS
esr(config-subscriber-control)# nas-ip-address
192.0
.
2.1
esr(config-subscriber-control)# session mac-authentication
esr(config-subscriber-control)# bypass-traffic-acl DHCP
esr(config-subscriber-control)#
default
-service
esr(config-subscriber-
default
-service)#
class
-map INTERNET
esr(config-subscriber-
default
-service)# filter-name local defaultservice
esr(config-subscriber-
default
-service)# filter-action permit
esr(config-subscriber-
default
-service)#
default
-action redirect http:
//192.0.2.20:8080/
eltex_portal/
esr(config-subscriber-
default
-service)# session-timeout
3600
esr(config-subscriber-
default
-service)# exit
esr(config-subscriber-control)# enable
esr(config-subscriber-control)# exit
Содержание ESR Series
Страница 218: ...ESR Series User manual 218 ...
Страница 234: ...ESR Series User manual 234 In addition to RIP protocol configuration open UDP port 520 in the firewall ...
Страница 306: ...ESR Series User manual 306 Parameter targeted LDP Hold timer 45 seconds Keepalive holdtime 180 seconds ...
Страница 452: ...ESR Series User manual 452 Step Description Command Keys 4 Enable Tracking object esr config tracking enable ...
Страница 514: ...ESR Series User manual 514 esr show ntp peers ...