187
Step Command
Remarks
3.
Configure Layer-2 portal
authentication.
See "
"
MAC-based access control.
HP does not recommend you
configure 802.1X guest VLANs
for triple authentication.
Triple authentication configuration examples
Triple authentication basic function configuration example
Network requirements
As shown in
, the terminals are connected to a switch to access the IP network. Configure triple
authentication on the Layer-2 interface of the switch that connects to the terminals so that a terminal
passing one of the three authentication methods, 802.1X authentication, portal authentication, and MAC
authentication, can access the IP network.
•
Configure static IP addresses in network 192.168.1.0/24 for the terminals.
•
Use the remote RADIUS server to perform authentication, authorization, and accounting and
configure the switch to send usernames carrying no ISP domain names to the RADIUS server.
•
The local portal authentication server on the switch uses listening IP address 4.4.4.4. The switch
sends a default authentication page to the web user and forwards authentication data using HTTP.
Figure 71
Network diagram
Configuration procedure
Make sure that the terminals, the server, and the switch can reach each other.
The host of the web user must have a route to the listening IP address of the local portal server.
1.
Configure the RADIUS server, and make sure the authentication, authorization, and accounting
functions work normally. In this example, configure on the RADIUS server an 802.1X user (with
username
userdot
), a portal user (with username
userpt
), and a MAC authentication user (with a
username and password both being the MAC address of the printer
001588f80dd7
).
2.
Configure portal authentication:
# Configure VLANs and IP addresses for the VLAN interfaces, and add ports to specific VLANs.
(Details not shown.)