R3721-F3210-F3171-HP High-End Firewalls Access Control Configuration Guide-6PW101
226
Error: Invalid configuration or no response from the authentication server.
Info: Change authentication mode to local.
Password: Å Enter the password for local privilege level switch authentication
User privilege level is 3, and only those commands can be used
whose level is equal or less than this.
Privilege note: 0-VISIT, 1-MONITOR, 2-SYSTEM, 3-MANAGE
AAA for portal users by a RADIUS server
Network requirements
As shown in Figure 165, the host automatically obtains a public network IP address through DHCP.
Configure Firewall to:
• Use the RADIUS server for authentication, authorization, and accounting of portal users.
• Provide direct portal authentication so that the host can access only the portal server before passing
portal authentication and can access the Internet after passing portal authentication.
• Include the domain name in a username sent to the RADIUS server.
On the RADIUS server, add a service that charges 120 dollars for up to 120 hours per month, configure
a user with the name dot1x@bbb, and assign the service to the user.
Set the shared keys for secure RADIUS communication to expert. Set the ports for
authentication/authorization and accounting to 1812 and 1813 respectively.
Figure 165 Network diagram
Configuration prerequisites
Configure IP addresses for the devices as shown in Figure 165 and make sure that devices have IP
connectivity between each other.
Configuring the RADIUS server on IMC PLAT 5.0
This section uses IMC PL AT 5.0 (E0101H03), IMC UAM 5.0 SP1 (E0101P03) , and IMC 5.0 (E0101P01) .
1. Add SecPath to IMC as an access device:
a. Log in to IMC, click the Service tab, and then select User Access Manager > Access Device
Management > Access Device from the navigation tree.
b. Click Add to configure an access device as follows:
Set the shared key for authentication and accounting to expert.