R3303-HP HSR6800 Routers Security Configuration Guide

64
Password: Å Enter the password for RADIUS privilege level switching authentication.
Error: Invalid configuration or no response from the authentication server.
Info: Change authentication mode to local.
Password: Å Enter the password for local privilege level switching authentication.
User privilege level is 3, and only those commands can be used
whose level is equal or less than this.
Privilege note: 0-VISIT, 1-MONITOR, 2-SYSTEM, 3-MANAGE
AAA for portal users by a RADIUS server
Network requirements
As shown in Figure 18, the host automatically obtains a public network IP address through DHCP.
Configure the router to:
Use the RADIUS server for authentication/authorization of portal users.
Provide direct portal authentication so that the host can access only the portal server before passing
portal authentication and can access the Internet after passing portal authentication.
Include the domain name in a username sent to the RADIUS server.
On the RADIUS server, add a service that charges 120 dollars for up to 120 hours per month, and
configure a user and register the service for the user.
Set the shared keys for secure RADIUS communication to expert. Set the ports for
authentication/authorization to 1812, respectively.
Figure 18 Network diagram
Configuration prerequisites
Configure IP addresses for the devices as shown in Figure 18 and make sure that devices can reach each
other. (Details not shown.)
Configuring the RADIUS server
This section assumes that the RADIUS server runs on IMC PLAT 5.1 SP1 (E0202P05) and IMC UAM 5.1
(E0301).
1. Add the router to the IMC Platform as an access device:
a. Log in to IMC, click the Service tab, and then select User Access Manager > Access Device
Management > Access Device from the navigation tree.
Internet
Router
Portal user
192.168.1.58/24
Gateway : 192.168.1.70/24
RADIUS server / Portal server
10.1.1.1/24
GE3/0/1
192.168.1.70/24
GE3/0/2
10.1.1.2/24