193
Bas-ip: Not configured
User detection: Not configured
Action for server detection:
Server type Server name Action
-- -- --
Layer3 source network:
IP address Prefix length
Destination authenticate subnet:
IP address Prefix length
Before passing portal authentication, a user that uses the HPE iNode client can access only the
authentication page
http://192.168.0.111:8080/portal
. All Web requests from the user will be
redirected to the authentication page.
•
The user can access the resources permitted by ACL 3000 after passing only identity
authentication.
•
The user can access network resources permitted by ACL 3001 after passing both identity
authentication and security check.
# After the user passes identity authentication and security check, use the following command to
display information about the portal user.
[SwitchA] display portal user interface vlan-interface 4
Total portal users: 1
Username: abc
Portal server: newpt
State: Online
VPN instance: N/A
MAC IP VLAN Interface
0015-e9a6-7cfe 8.8.8.2 4 Vlan-interface4
Authorization information:
DHCP IP pool: N/A
User profile: N/A
Session group profile: N/A
ACL: 3001
CAR: N/A
Configuring portal server detection and portal user
synchronization
Network requirements
As shown in
, the host is directly connected to the switch (the access device). The host is
assigned a public IP address either manually or through DHCP. A portal server acts as both a portal
authentication server and a portal Web server. A RADIUS server acts as the
authentication/accounting server.
•
Configure direct portal authentication on the switch, so the host can access only the portal
server before passing the authentication and access other network resources after passing the
authentication.
•
Configure the switch to detect the reachability state of the portal authentication server, send log
messages upon state changes, and disable portal authentication when the authentication
server is unreachable.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...