201
Verifying the configuration
# Use the following command to display information about the portal authentication server.
[Switch] display portal server newpt
Portal server: newpt
Type : IMC
IP : 192.168.0.111
VPN instance : Not configured
Port : 50100
Server Detection : Timeout 40s Action: log
User synchronization : Timeout 600s
Status : Up
The
Up
status of the portal authentication server indicates that the portal authentication server is
reachable. If the access device detects that the portal authentication server is unreachable, the
Status
field in the command output displays
Down
. The access device generates a server
unreachable log "Portal server newpt turns down from up." and disables portal authentication on the
access interface, so the host can access the external network without authentication.
Configuring direct portal authentication with a
preauthentication domain
Network requirements
As shown in
, the host is directly connected to the switch (the access device). The host is
assigned a public IP address through DHCP. A portal server acts as both a portal authentication
server and a portal Web server. A RADIUS server acts as the authentication/accounting server.
Configure direct portal authentication, so the host can access only subnet 192.168.0.0/24 before
passing the authentication and access other network resources after passing the authentication.
Figure 72 Network diagram
Configuration prerequisites
•
Configure IP addresses for the host, switch, and servers as shown in
and make sure
they can reach each other.
•
Configure the RADIUS server correctly to provide authentication and accounting functions.
Configuration procedure
Perform the following tasks on the switch.
1.
Configure a preauthentication IP address pool:
# Configure DHCP address pool
pre
to assign IP addresses and other configuration
parameters to clients on subnet 2.2.2.0/24.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...