H3C AC V7 在接口下配置Portal认证

简介:

[Nington_WX3510H_01]dis current-configuration 
#
version 7.1.064, Release 5117P14
#
sysname Nington_WX3510H_01
#
telnet server enable
#
irf mac-address persistent timer
irf auto-update enable
irf auto-merge enable
irf member 1 priority 1
#
dhcp enable
dhcp server forbidden-ip 10.123.160.1
dhcp server forbidden-ip 10.123.160.254
dhcp server forbidden-ip 10.123.161.1
#
password-recovery enable
#
vlan 1
#
vlan 30
name server

vlan 160
name ap
#
vlan 161
name yewu
#
irf-port 1
#
dhcp server ip-pool ap
gateway-list 10.123.160.1
network 10.123.160.0 mask 255.255.255.0
dns-list 114.114.114.114
#
dhcp server ip-pool client
gateway-list 10.123.161.1
network 10.123.161.0 mask 255.255.255.0
dns-list 114.114.114.114
#
wlan service-template 1
ssid ND_H3CV7_LY
vlan 161
service-template enable

interface NULL0
#
interface Vlan-interface1
#
interface Vlan-interface160
ip address 10.123.160.1 255.255.255.0
#
interface Vlan-interface161
ip address 10.123.161.1 255.255.255.0
portal enable method direct
portal domain h3c
portal bas-ip 10.123.161.1
portal apply web-server am
portal apply mac-trigger-server ndkey
#
interface GigabitEthernet1/0/1
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 30 160 to 161
#
interface GigabitEthernet1/0/2
port access vlan 160

interface GigabitEthernet1/0/3
port access vlan 30
#
interface GigabitEthernet1/0/4
#
interface GigabitEthernet1/0/5
#
interface GigabitEthernet1/0/6
#
interface GigabitEthernet1/0/7
#
interface GigabitEthernet1/0/8
#
scheduler logfile size 16
#
line class console
user-role network-admin
#
line class vty
user-role network-operator
#
line con 0
user-role network-admin
#
line vty 0 31
authentication-mode scheme
user-role network-operator
#
ip route-static 0.0.0.0 0 10.123.160.254
#
undo info-center logfile enable
#
radius session-control enable
#
radius scheme ndkey
primary authentication 192.168.222.192
primary accounting 192.168.222.192
key authentication cipher $c$3$ClvnzXNvJ4PpSXqebcZteQ2oKWOCJhCCAcaI
key accounting cipher $c$3$8vEW89B7vX89KWhLYj1i9i8HcwfI92FWkdSZ
user-name-format without-domain
nas-ip 10.123.161.1
#
radius dynamic-author server 
client ip 192.168.222.192 key cipher $c$3$KNxbCQYq4Rn0oNh6CHZrwSt6c34fkEm97XBJ
#
domain h3c 
authentication portal radius-scheme ndkey
authorization portal radius-scheme ndkey
accounting portal radius-scheme ndkey
#
domain system
#
domain default enable h3c
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role

role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
password hash $h$6$ey/uCDUk7m/eB+jx$0UepqE4Q46BMbZ7GrirRfhIUvBI/wLULX7YumphlgHk4EVos8RV4LZ8Ht7/TAlPXANTN5wWjwY+2k4jZguwKsA==
service-type telnet http https
authorization-attribute user-role network-admin
#
portal free-rule 1 source ip any destination ip 192.168.3.0 255.255.255.0
portal free-rule 2 source ip any destination ip 8.8.8.8 255.255.255.255
portal free-rule 3 source ip any destination ip 10.123.160.0 255.255.255.0
portal free-rule 4 source ip any destination ip 114.114.114.0 255.255.255.0
portal free-rule 5 source ip any destination ip 192.168.222.0 255.255.255.0
#
portal web-server am
url http://192.168.222.192:8080/am/portal/serviceId/SN1727240520/ac/H3CV7/ssid/ND_H3CV7_LY
server-type cmcc
url-parameter ssid ssid
url-parameter wlanacname value AC
url-parameter wlanuserip source-address
url-parameter wlanusermac source-mac
#
portal server am
ip 192.168.222.192 key cipher $c$3$i5xPYE7u5raqnCiogF0PONSz9EB6brmzDZn9
server-type cmcc
#
ip http enable
ip https enable
#
portal mac-trigger-server ndkey
ip 192.168.222.192
server-type cmcc
aaa-fail nobinding enable
#
wlan auto-ap enable
wlan auto-persistent enable
#
wlan global-configuration
firmware-upgrade enable

wlan ap-group default-group
vlan 1
#
wlan ap ap-01 model WA4320i-ACN 
serial-id 210235A1GPC163001309
vlan 1
radio 1
radio enable
service-template 1
radio 2
radio enable
service-template 1
gigabitethernet 1
gigabitethernet 2
#
return



本文转自    msft 博客,原文链接:     http://blog.51cto.com/victorly/2058224   如需转载请自行联系原作者


相关文章
|
7月前
|
XML 数据格式
一键修改手机型号,序列号修改器, 免root改手机机型【串号imei机型sn码】
这个Xposed模块实现了设备串号和型号的修改功能,包含主模块类
|
5月前
|
存储 存储控制器 Windows
错误代码0x80070570解决办法
错误代码0x80070570通常与文件系统损坏或硬件问题相关,以下是综合解决方案:
2376 24
|
6月前
|
应用服务中间件 Linux 网络安全
使用Nginx免费版与Keepalived实现高可用性High Availablity方案
本文介绍了如何使用Nginx免费版与Keepalived实现高可用性(HA)方案,涵盖环境搭建、Keepalived安装配置、版本升级及主从模式设置。通过虚拟机测试,结合CentOS与宝塔,详细说明VIP配置与服务启动流程,助你构建稳定可靠的Web高可用架构。
|
网络协议 安全 网络虚拟化
思科交换机配置命令归纳
【11月更文挑战第8天】本文总结了思科交换机的常见配置命令,包括模式转换、基本配置、查看命令、VLAN 配置、Trunk 配置、以太网通道配置、VTP 配置、三层交换机配置、生成树配置以及其他常用命令,适用于网络管理和维护。
1404 2
|
前端开发 JavaScript
构建你的第一个Web应用:从零到部署
【8月更文挑战第33天】 在这篇文章中,我们将一起踏上构建一个基本Web应用的旅程。不同于传统的“安装这个、运行那个”教程,我们的目标是通过理解每一步的意义和目的来深化你的技术理解。我们将探索HTML、CSS、JavaScript的基础,并学习如何将它们结合起来创建一个简单的个人网站。接着,我们会介绍如何使用GitHub Pages进行免费部署,让你的应用上线。准备好了吗?让我们开始吧!
610 5
|
JavaScript
vue 农历日期转公历日期(含插件 js-calendar-converter 使用教程)
vue 农历日期转公历日期(含插件 js-calendar-converter 使用教程)
593 0
|
SQL 关系型数据库 数据库
在 PostgreSQL 中使用 LIKE
【8月更文挑战第12天】
2070 1
|
负载均衡 网络协议 网络架构
|
存储 Python
`tempfile`模块在Python中用于创建临时文件和目录。
`tempfile`模块在Python中用于创建临时文件和目录。
|
Linux
linux系统如何使用GPT工具进行分区
linux系统如何使用GPT工具进行分区
720 2