Portal Authentication Across Vpns; Portal Configuration Task List - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

ACL assignment
The device uses ACLs to control user access to network resources and limit user access rights. With
authorized ACLs specified on the authentication server, when a user passes authentication, the
authentication server assigns an authorized ACL to the user, and the device filters traffic from the user on
the access port according to the authorized ACL. You must configure the authorized ACLs on the access
device if you specify authorized ACLs on the authentication server. To change the access right of a user,
specify a different authorized ACL on the authentication server or change the rules of the corresponding
authorized ACL on the device.

Portal authentication across VPNs

In a scenario where the branches belong to different VPNs that are isolated from each other and all
portal users in the branches need to be authenticated by the server at the headquarters, you can deploy
portal authentication across MPLS VPNs. As shown in
clients serves as the NAS. The NAS is configured with portal authentication and AAA authentication,
both of which support authentication across VPNs. The NAS can transparently transmit a client's portal
authentication packets in a VPN through the MPLS backbone to the servers in another VPN. This feature
implements centralized authentication of clients present in different VPNs while ensuring the separation
of packets of different VPNs.
For information about AAA implementation across VPNs, see
Figure 38 Network diagram for portal authentication across VPNs
VPN 1
Host
VPN 2
Host
NOTE:
Portal authentication configured on MCE devices can also support authentication across VPNs. For
information about MCE, see
This feature is not applicable to VPNs with overlapping address spaces.

Portal configuration task list

Task
Specifying the portal server
Enabling portal authentication
Controlling access of portal
CE
NAS
PE
CE
MPLS Configuration Guide
Configuring a portal-free rule
Figure
MPLS backbone
PE
P
.
108
38, the PE connecting the authentication
"Configuring
AAA."
VPN 3
AAA
server
CE
Portal server
Remarks
Required.
Required.
Optional.

Advertisement

Table of Contents
loading

Table of Contents