Specifying A Portal Authentication Domain; Configuring Radius Related Attributes; Specifying Nas-Port-Type For An Interface - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Set the maximum number of
online portal users.
The maximum number of online portal users the switch actually assigns depends on the ACL resources on
the switch.
If the maximum number of online portal users specified in the command is less than that of the current
online portal users, the command can be executed successfully and does not impact the online portal
users, but the system does not allow new portal users to log on until the number drops down below the
limit.

Specifying a portal authentication domain

After you specify an authentication domain for portal users on an interface, the device uses the
authentication domain for authentication, authorization, and accounting of all portal users on the
interface, ignoring the domain names carried in the usernames. This allows you to specify different
authentication domains for different interfaces as needed.
To specify the authentication domain for portal users on an interface:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Specify an authentication
domain for portal users on the
interface.
The device selects the authentication domain for a portal user on an interface in this order: the
authentication domain specified for the interface, the authentication domain carried in the username,
and the system default authentication domain. For information about the default authentication domain,
see
"Configuring

Configuring RADIUS related attributes

This section describes the RADIUS attributes that you can configure.

Specifying NAS-Port-Type for an interface

NAS-Port-Type is a standard RADIUS attribute for indicating a user access port type. With this attribute
specified on an interface, when a portal user logs on from the interface, the device uses the specified
NAS-Port-Type value as that in the RADIUS request to be sent to the RADIUS server. If NAS-Port-Type is not
specified, the device uses the access port type obtained.
If there are multiple network devices between the BAS (the portal authentication access device) and a
portal client, the BAS may not be able to obtain a user's correct access port information. For example, for
Command
system-view
portal max-user max-number
Command
system-view
interface interface-type
interface-number
portal domain [ ipv6 ]
domain-name
AAA."
136
Remarks
N/A
The default maximum number of
online portal users allowed is
6000.
Remarks
N/A
N/A
By default, no authentication
domain is specified for portal
users.

Advertisement

Table of Contents
loading

Table of Contents