R3303-HP HSR6800 Routers Security Configuration Guide

70
[Router] interface gigabitethernet 3/0/1
[Router-GigabitEthernet3/0/1] portal server newpt method direct
[Router-GigabitEthernet3/0/1] quit
Verifying the configuration
The user can initiate portal authentication by using the HP iNode client or by accessing a Web page. All
the initiated Web requests will be redirected to the portal authentication page at
http://10.1.1.1:8080/portal. Before passing portal authentication, the user can access only the
authentication page. After passing portal authentication, the user can access the Internet.
# After the user passes portal authentication, view the portal user information on the router.
[Router] display portal user interface gigabitethernet 3/0/1
Index:19
State:ONLINE
SubState:NONE
ACL:NONE
Work-mode:stand-alone
MAC IP Vlan Interface
---------------------------------------------------------------------
0015-e9a6-7cfe 192.168.1.58 0 GigabitEthernet3/0/1
On interface GigabitEthernet3/0/1:total 1 user(s) matched, 1 listed.
# View the connection information on the router.
[Router] display connection
Index=20 ,Username=portal@dm1
MAC=00-15-E9-A6-7C-FE
IP=192.168.1.58
IPv6=N/A
Total 1 connection(s) matched.
Troubleshooting AAA
Troubleshooting RADIUS
Symptom 1
User authentication/authorization always fails.
Analysis
Possible reasons include:
A communication failure exists between the NAS and the RADIUS server.
The username is not in the format userid@isp-name or the ISP domain is not correctly configured on
the NAS.
The user is not configured on the RADIUS server.
The password entered by the user is incorrect.
The RADIUS server and the NAS are configured with different shared keys.