HP VPN Firewall Appliances Access Control Configuration Guide

238
Error: Invalid configuration or no response from the authentication server.
Info: Change authentication mode to local.
Password: Å Enter the password for local privilege level switching authentication.
User privilege level is 3, and only those commands can be used
whose level is equal or less than this.
Privilege note: 0-VISIT, 1-MONITOR, 2-SYSTEM, 3-MANAGE
AAA configuration example for portal users by a RADIUS
server
Network requirements
As shown in Figure 142, the host automatically obtains a public network IP address through DHCP.
Configure the firewall to:
Use the RADIUS server for authentication, authorization, and accounting of portal users.
Provide direct portal authentication so that the host can access only the portal server before passing
portal authentication and can access the Internet after passing portal authentication.
Include the domain name in a username sent to the RADIUS server.
On the RADIUS server, add a service that charges 120 dollars for up to 120 hours per month, and
configure a user and register the service for the user.
Set the shared keys for secure RADIUS communication to expert. Set the ports for
authentication/authorization and accounting to 1812 and 1813, respectively.
Figure 142 Network diagram
Configuration prerequisites
Configure IP addresses for the devices as shown in Figure 142 and make sure that devices can reach
each other. (Details not shown.)
Configuring the RADIUS server
For information about the RADIUS server configuration, see the configuration guides of the RADIUS
server.
Configuring the portal server
For information about the portal server configuration, see the configuration guides of the portal server.